Filtered by vendor Oretnom23
Subscribe
Total
761 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-49973 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list. | |||||
| CVE-2023-49971 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list. | |||||
| CVE-2023-49970 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | |||||
| CVE-2023-49969 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 4.3 MEDIUM |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | |||||
| CVE-2023-49968 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 7.3 HIGH |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | |||||
| CVE-2023-49548 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | |||||
| CVE-2023-49547 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | |||||
| CVE-2023-49546 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 8.8 HIGH |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | |||||
| CVE-2023-49545 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 7.5 HIGH |
| A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | |||||
| CVE-2023-49544 | 1 Oretnom23 | 1 Customer Support System | 2026-06-17 | N/A | 4.9 MEDIUM |
| A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php. | |||||
| CVE-2023-49540 | 1 Oretnom23 | 1 Book Store Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter. | |||||
| CVE-2023-49539 | 1 Oretnom23 | 1 Book Store Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter. | |||||
| CVE-2023-46956 | 1 Oretnom23 | 1 Packers And Movers Management System | 2026-06-17 | N/A | 7.2 HIGH |
| SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file. | |||||
| CVE-2023-46435 | 1 Oretnom23 | 1 Packers And Movers Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id. | |||||
| CVE-2023-44824 | 1 Oretnom23 | 1 Expense Management System | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component. | |||||
| CVE-2023-44752 | 1 Oretnom23 | 1 Student Study Center Desk Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php. | |||||
| CVE-2023-44048 | 1 Oretnom23 | 1 Expense Tracker | 2026-06-17 | N/A | 5.4 MEDIUM |
| Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category. | |||||
| CVE-2023-44047 | 1 Oretnom23 | 1 Toll Tax Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection. | |||||
| CVE-2023-43944 | 1 Oretnom23 | 1 Task Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list. | |||||
| CVE-2023-43457 | 1 Oretnom23 | 1 Service Provider Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint. | |||||
