VendorsEngineers Online Portal Projectengineers_online_portal1.0
Vulnerabilities

Engineers Online Portal Project Engineers Online Portal 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2021-42665
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
Published 2021-11-05 · Modified
9.8EPSS 0.049
CVE-2023-5277
SourceCodester Engineers Online Portal student_avatar.php unrestricted upload
Published 2023-09-29 · Modified
9.8EPSS 0.008
CVE-2023-5278
SourceCodester Engineers Online Portal login.php sql injection
Published 2023-09-29 · Modified
9.8EPSS 0.007
CVE-2023-5281
SourceCodester Engineers Online Portal remove_inbox_message.php sql injection
Published 2023-09-29 · Modified
9.8EPSS 0.007
CVE-2023-5282
SourceCodester Engineers Online Portal seed_message_student.php sql injection
Published 2023-09-29 · Modified
9.8EPSS 0.007
CVE-2023-5280
SourceCodester Engineers Online Portal my_students.php sql injection
Published 2023-09-29 · Modified
9.8EPSS 0.007
CVE-2023-5279
SourceCodester Engineers Online Portal my_classmates.php sql injection
Published 2023-09-29 · Modified
9.8EPSS 0.007
CVE-2023-5276
SourceCodester Engineers Online Portal downloadable_student.php sql injection
Published 2023-09-29 · Modified
9.8EPSS 0.007
CVE-2021-42666
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.
Published 2021-11-05 · Modified
8.8EPSS 0.045
CVE-2021-43437
In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the same IP address. This is where the Host Header comes in. This header specifies which website should process the HTTP request. The web server uses the value of this header to dispatch the request to the specified website. Each website hosted on the same IP address is called a virtual host. And It's possible to send requests with arbitrary Host Headers to the first virtual host.
Published 2021-12-20 · Modified
8.8EPSS 0.012
CVE-2023-5284
SourceCodester Engineers Online Portal upload_save_student.php unrestricted upload
Published 2023-09-29 · Modified
8.8EPSS 0.008
CVE-2023-5283
SourceCodester Engineers Online Portal teacher_signup.php sql injection
Published 2023-09-29 · Modified
8.8EPSS 0.006
CVE-2024-0260
SourceCodester Engineers Online Portal Password Change change_password_teacher.php session expiration
Published 2024-01-07 · Modified
7.5EPSS 0.005
CVE-2024-0348
SourceCodester Engineers Online Portal File Upload resource consumption
Published 2024-01-09 · Modified
6.5EPSS 0.011
CVE-2024-0350
SourceCodester Engineers Online Portal session expiration
Published 2024-01-09 · Modified
6.5EPSS 0.005
CVE-2021-42664
A Stored Cross Site Scripting (XSS) Vulneraibiilty exists in Sourcecodester Engineers Online Portal in PHP via the (1) Quiz title and (2) quiz description parameters to add_quiz.php. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
Published 2021-11-05 · Modified
5.4EPSS 0.017
CVE-2024-0349
SourceCodester Engineers Online Portal missing secure attribute
Published 2024-01-09 · Modified
5.3EPSS 0.004
CVE-2024-0347
SourceCodester Engineers Online Portal signup_teacher.php weak password
Published 2024-01-09 · Modified
3.7EPSS 0.009
CVE-2024-0351
SourceCodester Engineers Online Portal session fixiation
Published 2024-01-09 · Modified
3.5EPSS 0.006