VendorsCanteen Management System Projectcanteen_management_systemall versions
Vulnerabilities

Canteen Management System Project Canteen Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2022-43265
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-11-15 · Modified
9.8EPSS 0.010
CVE-2023-23279
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
Published 2023-02-17 · Modified
9.8EPSS 0.009
CVE-2023-1475
SourceCodester Canteen Management System createuser.php query sql injection
Published 2023-03-17 · Modified
9.8EPSS 0.008
CVE-2023-1461
SourceCodester Canteen Management System createCategories.php query sql injection
Published 2023-03-17 · Modified
9.8EPSS 0.008
CVE-2023-1459
SourceCodester Canteen Management System changeUsername.php sql injection
Published 2023-03-17 · Modified
9.8EPSS 0.008
CVE-2023-0781
SourceCodester Canteen Management System removeOrder.php query sql injection
Published 2023-02-11 · Modified
9.8EPSS 0.007
CVE-2022-3583
SourceCodester Canteen Management System login.php sql injection
Published 2022-10-18 · Modified
9.8EPSS 0.007
CVE-2022-4222
SourceCodester Canteen Management System POST Request ajax_invoice.php query sql injection
Published 2022-11-30 · Modified
9.8EPSS 0.007
CVE-2022-3584
SourceCodester Canteen Management System edituser.php sql injection
Published 2022-10-18 · Modified
8.8EPSS 0.007
CVE-2022-4403
SourceCodester Canteen Management System ajax_represent.php sql injection
Published 2022-12-11 · Modified
8.8EPSS 0.006
CVE-2023-0679
SourceCodester Canteen Management System removeUser.php sql injection
Published 2023-02-06 · Modified
8.1EPSS 0.007
CVE-2022-43231
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-10-28 · Modified
7.2EPSS 0.011
CVE-2022-43146
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-11-14 · Modified
7.2EPSS 0.011
CVE-2022-43277
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-11-09 · Modified
7.2EPSS 0.010
CVE-2022-43275
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-10-28 · Modified
7.2EPSS 0.010
CVE-2022-43232
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php.
Published 2022-10-28 · Modified
7.2EPSS 0.008
CVE-2022-43233
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php.
Published 2022-10-28 · Modified
7.2EPSS 0.008
CVE-2022-43276
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php.
Published 2022-10-28 · Modified
7.2EPSS 0.008
CVE-2022-43049
Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youthappam/add-food.php.
Published 2022-11-07 · Modified
7.2EPSS 0.008
CVE-2022-43278
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at /php_action/fetchSelectedCategories.php.
Published 2022-11-09 · Modified
7.2EPSS 0.008
CVE-2022-43290
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editcategory.php.
Published 2022-11-09 · Modified
7.2EPSS 0.008
CVE-2022-43291
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editclient.php.
Published 2022-11-09 · Modified
7.2EPSS 0.008
CVE-2022-43292
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editfood.php.
Published 2022-11-09 · Modified
7.2EPSS 0.008
CVE-2022-43330
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
Published 2022-11-01 · Modified
7.2EPSS 0.006
CVE-2022-43331
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php.
Published 2022-11-01 · Modified
7.2EPSS 0.006
CVE-2022-43329
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
Published 2022-11-01 · Modified
7.2EPSS 0.006
CVE-2022-43328
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
Published 2022-11-01 · Modified
7.2EPSS 0.006
CVE-2022-4091
SourceCodester Canteen Management System food.php query cross site scripting
Published 2022-11-25 · Modified
6.1EPSS 0.004
CVE-2022-4252
SourceCodester Canteen Management System categories.php builtin_echo cross site scripting
Published 2022-12-01 · Modified
6.1EPSS 0.004
CVE-2022-4234
SourceCodester Canteen Management System brand.php builtin_echo cross site scripting
Published 2022-11-30 · Modified
6.1EPSS 0.004
CVE-2022-43144
A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published 2022-11-08 · Modified
5.4EPSS 0.010
CVE-2023-0571
SourceCodester Canteen Management System Add Customer createcustomer.php cross site scripting
Published 2023-01-29 · Modified
5.4EPSS 0.006
CVE-2022-4253
SourceCodester Canteen Management System customer.php builtin_echo cross site scripting
Published 2022-12-01 · Modified
5.4EPSS 0.004