VendorsBilling System Projectbilling_systemall versions
Vulnerabilities

Billing System Project Billing System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-43214
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.
Published 2022-11-22 · Modified
9.8EPSS 0.009
CVE-2022-43215
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.
Published 2022-11-22 · Modified
9.8EPSS 0.009
CVE-2022-41504
An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-10-18 · Modified
7.2EPSS 0.011
CVE-2022-41498
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.
Published 2022-10-17 · Modified
7.2EPSS 0.008