VendorsBook Store Management System Projectbook_store_management_systemall versions
Vulnerabilities

Book Store Management System Project Book Store Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-49543
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.
Published 2024-03-01 · Analyzed
9.8EPSS 0.010
CVE-2022-4229
SourceCodester Book Store Management System index.php access control
Published 2022-11-30 · Modified
9.8EPSS 0.009
CVE-2022-44097
Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
Published 2022-11-30 · Modified
9.8EPSS 0.008
CVE-2022-4228
SourceCodester Book Store Management System information disclosure
Published 2022-11-30 · Modified
7.5EPSS 0.012
CVE-2022-45225
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_title parameter.
Published 2022-11-25 · Modified
6.1EPSS 0.005
CVE-2023-23024
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter.
Published 2023-01-20 · Modified
6.1EPSS 0.004
CVE-2022-45217
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.
Published 2022-12-07 · Modified
5.4EPSS 0.006
CVE-2022-45613
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the publisher parameter.
Published 2023-01-18 · Modified
5.4EPSS 0.005
CVE-2022-3452
SourceCodester Book Store Management System category.php cross site scripting
Published 2022-10-11 · Modified
5.4EPSS 0.004
CVE-2022-3453
SourceCodester Book Store Management System transcation.php cross site scripting
Published 2022-10-11 · Modified
5.4EPSS 0.004
CVE-2022-45215
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the Add New System User module.
Published 2022-12-02 · Modified
5.4EPSS 0.004