VendorsBarangay Management System Projectbarangay_management_systemall versions
Vulnerabilities

Barangay Management System Project Barangay Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-35175
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php.
Published 2022-08-18 · Modified
9.8EPSS 0.010
CVE-2022-34023
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.
Published 2022-07-19 · Modified
9.8EPSS 0.008
CVE-2022-34557
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php.
Published 2022-07-28 · Modified
8.8EPSS 0.009
CVE-2022-34120
Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php.
Published 2022-07-27 · Modified
7.2EPSS 0.192
CVE-2022-34024
Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.
Published 2022-07-19 · Modified
7.2EPSS 0.014
CVE-2022-34042
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php.
Published 2022-07-20 · Modified
7.2EPSS 0.009
CVE-2022-43228
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.
Published 2022-10-28 · Modified
7.2EPSS 0.008
CVE-2024-25208
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter.
Published 2024-02-14 · Modified
5.4EPSS 0.004
CVE-2024-25207
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Contact Number parameter.
Published 2024-02-14 · Modified
5.4EPSS 0.004