VendorsCode-Projectssimple_school_management_system1.0
Vulnerabilities

Code-Projects Simple School Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-25305
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.
Published 2024-02-09 · Modified
8.8EPSS 0.009
CVE-2024-25313
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.
Published 2024-02-09 · Modified
8.8EPSS 0.008
CVE-2024-25306
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
Published 2024-02-09 · Modified
8.8EPSS 0.007
CVE-2024-25308
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.
Published 2024-02-09 · Modified
8.8EPSS 0.007
CVE-2024-25310
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."
Published 2024-02-09 · Modified
8.8EPSS 0.007
CVE-2024-25304
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
Published 2024-02-09 · Modified
8.8EPSS 0.007
CVE-2024-25309
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.
Published 2024-02-09 · Modified
8.8EPSS 0.007
CVE-2024-25312
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."
Published 2024-02-09 · Modified
8.8EPSS 0.007
CVE-2024-31610
File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.
Published 2024-04-25 · Analyzed
6.3EPSS 0.004