Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Total 761 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-3140 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file /classes/Users.php?f=save. The manipulation of the argument middlename leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258915.
CVE-2024-3139 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 5.5 MEDIUM 5.4 MEDIUM
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-258914 is the identifier assigned to this vulnerability.
CVE-2024-3131 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=save_category. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258874 is the identifier assigned to this vulnerability.
CVE-2024-3042 1 Oretnom23 1 Simple Subscription Website 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258431.
CVE-2024-3015 1 Oretnom23 1 Simple Subscription Website 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in SourceCodester Simple Subscription Website 1.0. Affected by this vulnerability is an unknown functionality of the file manage_plan.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258301 was assigned to this vulnerability.
CVE-2024-3014 1 Oretnom23 1 Simple Subscription Website 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in SourceCodester Simple Subscription Website 1.0. Affected is an unknown function of the file Actions.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258300.
CVE-2024-35583 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Remarks input field.
CVE-2024-35582 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.
CVE-2024-35581 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
CVE-2024-35469 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVE-2024-35468 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVE-2024-34833 1 Oretnom23 1 Payroll Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
CVE-2024-34480 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
CVE-2024-34479 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
CVE-2024-34226 1 Oretnom23 1 Visitor Management System 2026-06-17 N/A 9.4 CRITICAL
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.
CVE-2024-34225 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
CVE-2024-34224 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
CVE-2024-34223 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 4.3 MEDIUM
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
CVE-2024-34222 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 5.9 MEDIUM
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
CVE-2024-34221 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.