Vulnerabilities (CVE)

Filtered by vendor Mayurik Subscribe
Total 267 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-8966 1 Mayurik 1 Online Tour \& Travel Management System 2026-04-29 7.5 HIGH 7.3 HIGH
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/tax.php. The manipulation of the argument tname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-8982 1 Mayurik 1 Online Tour \& Travel Management System 2026-04-29 7.5 HIGH 7.3 HIGH
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/currency.php. The manipulation of the argument curr_code leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-12226 1 Mayurik 1 Best House Rental Management System 2026-04-29 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house of the file /admin_class.php. Performing manipulation of the argument house_no results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
CVE-2025-63717 1 Mayurik 1 Pet Grooming Management Software 2025-11-17 N/A 6.5 MEDIUM
The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attackers to trick authenticated users into unknowingly changing their passwords.
CVE-2025-63298 1 Mayurik 1 Pet Grooming Management Software 2025-11-06 N/A 8.2 HIGH
A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request, enabling the deletion of arbitrary files on the web server or underlying operating system.
CVE-2025-60316 1 Mayurik 1 Pet Grooming Management Software 2025-10-16 N/A 9.4 CRITICAL
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.
CVE-2025-60318 1 Mayurik 1 Pet Grooming Management Software 2025-10-09 N/A 6.1 MEDIUM
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields.
CVE-2025-61087 1 Mayurik 1 Pet Grooming Management Software 2025-10-07 N/A 6.1 MEDIUM
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.
CVE-2025-11051 1 Mayurik 1 Pet Grooming Management Software 2025-10-03 5.0 MEDIUM 4.3 MEDIUM
A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely.
CVE-2023-5270 1 Mayurik 1 Best Courier Management System 2025-09-30 5.2 MEDIUM 5.5 MEDIUM
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view_parcel.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240883.
CVE-2023-5271 1 Mayurik 1 Best Courier Management System 2025-09-30 5.2 MEDIUM 5.5 MEDIUM
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_parcel.php. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240884.
CVE-2023-5272 1 Mayurik 1 Best Courier Management System 2025-09-30 5.2 MEDIUM 5.5 MEDIUM
A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. This affects an unknown part of the file edit_parcel.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-240885 was assigned to this vulnerability.
CVE-2023-44755 1 Mayurik 1 Sacco Management System 2025-06-19 N/A 9.8 CRITICAL
Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.
CVE-2025-44184 1 Mayurik 1 Best Employee Management System 2025-05-28 N/A 4.8 MEDIUM
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.
CVE-2025-44185 1 Mayurik 1 Best Employee Management System 2025-05-28 N/A 5.4 MEDIUM
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.
CVE-2025-4728 1 Mayurik 1 Best Online News Portal 2025-05-27 7.5 HIGH 7.3 HIGH
A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-44186 1 Mayurik 1 Best Employee Management System 2025-05-27 N/A 5.4 MEDIUM
SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.
CVE-2025-1167 1 Mayurik 1 Employee Management System 2025-05-26 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknown functionality of the file /hr_soft/admin/Update_User.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-48411 1 Mayurik 1 Online Tours \& Travels Management System 2025-05-17 N/A 9.8 CRITICAL
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.
CVE-2025-2602 1 Mayurik 1 Advocate Office Management System 2025-05-14 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file deactivate_reg.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.