Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Total 761 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49973 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.
CVE-2023-49971 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.
CVE-2023-49970 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 9.8 CRITICAL
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.
CVE-2023-49969 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 4.3 MEDIUM
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.
CVE-2023-49968 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 7.3 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.
CVE-2023-49548 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.
CVE-2023-49547 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 9.8 CRITICAL
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.
CVE-2023-49546 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.
CVE-2023-49545 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 7.5 HIGH
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49544 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 4.9 MEDIUM
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
CVE-2023-49540 1 Oretnom23 1 Book Store Management System 2026-06-17 N/A 6.1 MEDIUM
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.
CVE-2023-49539 1 Oretnom23 1 Book Store Management System 2026-06-17 N/A 6.1 MEDIUM
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.
CVE-2023-46956 1 Oretnom23 1 Packers And Movers Management System 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.
CVE-2023-46435 1 Oretnom23 1 Packers And Movers Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.
CVE-2023-44824 1 Oretnom23 1 Expense Management System 2026-06-17 N/A 7.8 HIGH
An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.
CVE-2023-44752 1 Oretnom23 1 Student Study Center Desk Management System 2026-06-17 N/A 9.8 CRITICAL
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.
CVE-2023-44048 1 Oretnom23 1 Expense Tracker 2026-06-17 N/A 5.4 MEDIUM
Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.
CVE-2023-44047 1 Oretnom23 1 Toll Tax Management System 2026-06-17 N/A 7.2 HIGH
Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.
CVE-2023-43944 1 Oretnom23 1 Task Management System 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list.
CVE-2023-43457 1 Oretnom23 1 Service Provider Management System 2026-06-17 N/A 9.8 CRITICAL
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.