Vendorsoretnom23expense_management_system1.0
Vulnerabilities

oretnom23 Expense Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-44824
An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.
Published 2023-10-17 · Modified
7.8EPSS 0.003
CVE-2022-36754
Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p.
Published 2022-09-02 · Modified
7.2EPSS 0.009
CVE-2024-1031
CodeAstro Expense Management System Add Expenses Page 5-Add-Expenses.php cross site scripting
Published 2024-01-30 · Modified
6.1EPSS 0.004
CVE-2021-41434
A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.
Published 2022-09-28 · Modified
5.4EPSS 0.006