VendorsMayuri Kbest_house_rental_management_systemall versions
Vulnerabilities

Mayuri K Mayurik Best House Rental Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2024-6043
SourceCodester Best House Rental Management System admin_class.php login sql injection
Published 2024-06-17 · Modified
9.8EPSS 0.019
CVE-2024-46377
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.
Published 2024-09-18 · Analyzed
9.8EPSS 0.012
CVE-2024-46375
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.
Published 2024-09-18 · Analyzed
9.8EPSS 0.011
CVE-2024-46376
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.
Published 2024-09-18 · Analyzed
9.8EPSS 0.011
CVE-2024-48579
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
Published 2024-10-25 · Analyzed
9.8EPSS 0.009
CVE-2024-5094
SourceCodester Best House Rental Management System view_payment.php sql injection
Published 2024-05-18 · Analyzed
9.8EPSS 0.007
CVE-2024-9039
SourceCodester Best House Rental Management System ajax.php sql injection
Published 2024-09-20 · Analyzed
9.8EPSS 0.007
CVE-2024-5093
SourceCodester Best House Rental Management System login.php sql injection
Published 2024-05-18 · Analyzed
9.8EPSS 0.007
CVE-2024-10349
SourceCodester Best House Rental Management System ajax.php delete_tenant sql injection
Published 2024-10-24 · Analyzed
9.8EPSS 0.006
CVE-2024-6066
SourceCodester Best House Rental Management System payment_report.php sql injection
Published 2024-06-17 · Modified
9.8EPSS 0.005
CVE-2024-46374
Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.
Published 2024-09-18 · Analyzed
9.8EPSS 0.005
CVE-2025-12208
SourceCodester Best House Rental Management System admin_class.php login2 sql injection
Published 2025-10-27 · Analyzed
9.8EPSS 0.004
CVE-2025-12226
SourceCodester Best House Rental Management System admin_class.php save_house sql injection
Published 2025-10-27 · Analyzed
9.8EPSS 0.004
CVE-2025-12597
SourceCodester Best House Rental Management System admin_class.php save_category sql injection
Published 2025-11-02 · Analyzed
9.8EPSS 0.004
CVE-2025-12598
SourceCodester Best House Rental Management System admin_class.php save_tenant sql injection
Published 2025-11-02 · Analyzed
9.8EPSS 0.004
CVE-2025-12614
SourceCodester Best House Rental Management System admin_class.php delete_payment sql injection
Published 2025-11-03 · Analyzed
9.8EPSS 0.004
CVE-2025-12853
SourceCodester Best House Rental Management System admin_class.php delete_house sql injection
Published 2025-11-07 · Analyzed
9.8EPSS 0.003
CVE-2024-9041
SourceCodester Best House Rental Management System ajax.php sql injection
Published 2024-09-20 · Analyzed
8.8EPSS 0.006
CVE-2024-8709
SourceCodester Best House Rental Management System admin_class.php save_user sql injection
Published 2024-09-12 · Analyzed
8.8EPSS 0.006
CVE-2024-40475
SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.
Published 2024-08-08 · Analyzed
8.8EPSS 0.005
CVE-2024-40474
A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.
Published 2024-08-08 · Analyzed
8.8EPSS 0.005
CVE-2024-39210
Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers to read arbitrary PHP files and access other sensitive information within the application.
Published 2024-07-05 · Modified
7.5EPSS 0.008
CVE-2024-11860
SourceCodester Best House Rental Management System POST Request ajax.php improper authorization
Published 2024-11-27 · Analyzed
6.9EPSS 0.009
CVE-2024-12357
SourceCodester Best House Rental Management System index.php file inclusion
Published 2024-12-09 · Analyzed
6.9EPSS 0.004
CVE-2024-11743
SourceCodester Best House Rental Management System POST Request ajax.php cross-site request forgery
Published 2024-11-26 · Analyzed
6.9EPSS 0.003
CVE-2024-5366
SourceCodester Best House Rental Management System edit-cate.php sql injection
Published 2024-05-26 · Analyzed
6.5EPSS 0.005
CVE-2024-5364
SourceCodester Best House Rental Management System manage_tenant.php sql injection
Published 2024-05-26 · Analyzed
6.5EPSS 0.005
CVE-2024-5365
SourceCodester Best House Rental Management System manage_payment.php sql injection
Published 2024-05-26 · Analyzed
6.5EPSS 0.005
CVE-2024-5363
SourceCodester Best House Rental Management System manage_user.php sql injection
Published 2024-05-26 · Analyzed
6.5EPSS 0.005
CVE-2024-8708
SourceCodester Best House Rental Management System categories.php cross site scripting
Published 2024-09-12 · Analyzed
6.1EPSS 0.003
CVE-2024-40473
A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.
Published 2024-08-08 · Modified
5.4EPSS 0.006
CVE-2024-11742
SourceCodester Best House Rental Management System ajax.php cross site scripting
Published 2024-11-26 · Analyzed
5.4EPSS 0.005
CVE-2024-8610
SourceCodester Best House Rental Management System New Tenant Page index.php cross site scripting
Published 2024-09-09 · Analyzed
5.4EPSS 0.005
CVE-2024-9033
SourceCodester Best House Rental Management System ajax.php cross site scripting
Published 2024-09-20 · Analyzed
5.4EPSS 0.005
CVE-2024-7812
SourceCodester Best House Rental Management System POST Parameter ajax.php cross site scripting
Published 2024-08-15 · Analyzed
5.4EPSS 0.004
CVE-2024-10348
SourceCodester Best House Rental Management System Manage Tenant Details index.php cross site scripting
Published 2024-10-24 · Analyzed
5.4EPSS 0.004
CVE-2024-40576
Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component.
Published 2024-07-29 · Analyzed
4.7EPSS 0.008