Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Filtered by product Computer Laboratory Management System
Total 30 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-35581 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
CVE-2024-34480 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
CVE-2024-34479 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
CVE-2024-34225 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
CVE-2024-34224 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
CVE-2024-31586 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters.
CVE-2024-31547 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.1 CRITICAL
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.
CVE-2024-31546 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.
CVE-2024-31545 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.4 CRITICAL
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.
CVE-2024-31544 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, “borrower_name”, “faculty_department” parameters in /classes/Master.php?f=save_record.