VendorsMayuri Kpetrol_pump_managementall versions
Vulnerabilities

Mayuri K Petrol Pump Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2024-27747
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.
Published 2024-03-01 · Analyzed
9.81 PoCEPSS 0.236
CVE-2024-27746
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.
Published 2024-03-01 · Analyzed
9.81 PoCEPSS 0.129
CVE-2024-28558
SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin/app/web_crud.php.
Published 2024-04-15 · Analyzed
8.8EPSS 0.012
CVE-2024-10380
SourceCodester Petrol Pump Management Software ajax_product.php sql injection
Published 2024-10-25 · Analyzed
7.5EPSS 0.004
CVE-2024-2058
SourceCodester Petrol Pump Management Software product.php unrestricted upload
Published 2024-03-01 · Analyzed
7.2EPSS 0.006
CVE-2024-2059
SourceCodester Petrol Pump Management Software service_crud.php unrestricted upload
Published 2024-03-01 · Analyzed
7.2EPSS 0.006
CVE-2024-2061
SourceCodester Petrol Pump Management Software edit_supplier.php sql injection
Published 2024-03-01 · Analyzed
7.2EPSS 0.005
CVE-2024-2062
SourceCodester Petrol Pump Management Software edit_categories.php sql injection
Published 2024-03-01 · Analyzed
7.2EPSS 0.005
CVE-2024-2060
SourceCodester Petrol Pump Management Software login_crud.php sql injection
Published 2024-03-01 · Analyzed
7.2EPSS 0.005
CVE-2024-10406
SourceCodester Petrol Pump Management Software edit_fuel.php sql injection
Published 2024-10-26 · Analyzed
7.2EPSS 0.004
CVE-2024-10407
SourceCodester Petrol Pump Management Software edit_customer.php sql injection
Published 2024-10-26 · Analyzed
7.2EPSS 0.004
CVE-2024-27744
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.
Published 2024-03-01 · Analyzed
6.11 PoCEPSS 0.013
CVE-2024-27743
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component.
Published 2024-03-01 · Analyzed
6.11 PoCEPSS 0.013
CVE-2024-10355
SourceCodester Petrol Pump Management Software invoice.php sql injection
Published 2024-10-25 · Analyzed
5.8EPSS 0.010
CVE-2024-10354
SourceCodester Petrol Pump Management Software print.php sql injection
Published 2024-10-25 · Analyzed
5.8EPSS 0.007
CVE-2024-2063
SourceCodester Petrol Pump Management Software profile_crud.php cross site scripting
Published 2024-03-01 · Analyzed
4.8EPSS 0.004