Vendorsoretnom23computer_laboratory_management_systemall versions
Vulnerabilities

oretnom23 Computer Laboratory Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2024-3376
SourceCodester Computer Laboratory Management System config.php redirect
Published 2024-04-06 · Analyzed
9.8EPSS 0.013
CVE-2024-31546
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.
Published 2024-04-19 · Analyzed
9.8EPSS 0.007
CVE-2024-3315
SourceCodester Computer Laboratory Management System user.php sql injection
Published 2024-04-04 · Analyzed
9.8EPSS 0.007
CVE-2024-34479
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
Published 2024-08-07 · Analyzed
9.8EPSS 0.007
CVE-2024-34480
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
Published 2024-08-07 · Modified
9.8EPSS 0.006
CVE-2024-8348
SourceCodester Computer Laboratory Management System Master.php delete_category sql injection
Published 2024-08-30 · Analyzed
9.8EPSS 0.006
CVE-2024-8347
SourceCodester Computer Laboratory Management System Master.php delete_record sql injection
Published 2024-08-30 · Analyzed
9.8EPSS 0.006
CVE-2024-8346
SourceCodester Computer Laboratory Management System SystemSettings.php update_settings_info sql injection
Published 2024-08-30 · Analyzed
9.8EPSS 0.006
CVE-2024-3314
SourceCodester Computer Laboratory Management System Users.php sql injection
Published 2024-04-04 · Analyzed
9.8EPSS 0.005
CVE-2024-31545
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.
Published 2024-04-22 · Analyzed
9.4EPSS 0.006
CVE-2024-31547
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.
Published 2024-04-19 · Analyzed
9.1EPSS 0.006
CVE-2024-3251
SourceCodester Computer Laboratory Management System sql injection
Published 2024-04-03 · Analyzed
8.8EPSS 0.006
CVE-2024-3316
SourceCodester Computer Laboratory Management System view_category.php sql injection
Published 2024-04-04 · Analyzed
8.8EPSS 0.006
CVE-2024-54818
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.
Published 2025-01-08 · Analyzed
8.8EPSS 0.005
CVE-2025-45956
A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter
Published 2025-04-29 · Analyzed
8.8EPSS 0.005
CVE-2026-3770
SourceCodester Computer Laboratory Management System cross-site request forgery
Published 2026-03-08 · Analyzed
8.8EPSS 0.002
CVE-2024-34224
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
Published 2024-05-13 · Analyzed
7.3EPSS 0.009
CVE-2024-41332
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.
Published 2024-08-09 · Analyzed
6.5EPSS 0.006
CVE-2024-3131
SourceCodester Computer Laboratory Management System sql injection
Published 2024-04-01 · Analyzed
6.5EPSS 0.005
CVE-2024-3377
SourceCodester Computer Laboratory Management System cross site scripting
Published 2024-04-06 · Analyzed
6.1EPSS 0.006
CVE-2024-34225
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
Published 2024-05-13 · Analyzed
6.1EPSS 0.006
CVE-2024-31586
A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters.
Published 2024-06-20 · Analyzed
6.1EPSS 0.005
CVE-2024-35583
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Remarks input field.
Published 2024-05-28 · Analyzed
6.1EPSS 0.005
CVE-2024-35581
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
Published 2024-05-28 · Analyzed
6.1EPSS 0.004
CVE-2024-35582
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.
Published 2024-05-28 · Analyzed
6.1EPSS 0.004
CVE-2024-3139
SourceCodester Computer Laboratory Management System save_users improper authorization
Published 2024-04-01 · Analyzed
5.5EPSS 0.005
CVE-2024-3695
SourceCodester Computer Laboratory Management System Users.php cross site scripting
Published 2024-04-12 · Analyzed
5.4EPSS 0.006
CVE-2024-3140
SourceCodester Computer Laboratory Management System cross site scripting
Published 2024-04-01 · Analyzed
5.4EPSS 0.006
CVE-2024-31544
A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, “borrower_name”, “faculty_department” parameters in /classes/Master.php?f=save_record.
Published 2024-04-09 · Analyzed
5.4EPSS 0.004
CVE-2024-40443
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
Published 2024-11-13 · Analyzed
4.3EPSS 0.008