Vendorsoretnom23lost_and_found_information_systemall versions
Vulnerabilities

oretnom23 Lost and Found Information System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2023-33592
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
Published 2023-06-28 · Modified
9.81 PoCEPSS 0.038
CVE-2023-38965
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
Published 2023-11-03 · Modified
9.8EPSS 0.013
CVE-2023-2698
SourceCodester Lost and Found Information System GET Parameter sql injection
Published 2023-05-14 · Modified
9.8EPSS 0.008
CVE-2023-2699
SourceCodester Lost and Found Information System GET Parameter sql injection
Published 2023-05-14 · Modified
9.8EPSS 0.008
CVE-2023-2668
SourceCodester Lost and Found Information System GET Parameter manager_category sql injection
Published 2023-05-12 · Modified
9.8EPSS 0.008
CVE-2023-2669
SourceCodester Lost and Found Information System GET Parameter sql injection
Published 2023-05-12 · Modified
9.8EPSS 0.008
CVE-2024-37858
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.
Published 2024-07-29 · Modified
9.8EPSS 0.008
CVE-2023-2672
SourceCodester Lost and Found Information System GET Parameter view.php sql injection
Published 2023-05-12 · Modified
9.8EPSS 0.008
CVE-2023-2653
SourceCodester Lost and Found Information System index.php sql injection
Published 2023-05-11 · Modified
9.8EPSS 0.007
CVE-2023-2652
SourceCodester Lost and Found Information System sql injection
Published 2023-05-11 · Modified
9.8EPSS 0.007
CVE-2023-5018
SourceCodester Lost and Found Information System POST Parameter sql injection
Published 2023-09-17 · Modified
9.8EPSS 0.005
CVE-2023-3679
SourceCodester Lost and Found Information System HTTP POST Request sql injection
Published 2023-07-15 · Modified
9.8EPSS 0.005
CVE-2023-3680
SourceCodester Lost and Found Information System HTTP POST Request sql injection
Published 2023-07-15 · Modified
9.8EPSS 0.005
CVE-2023-3850
SourceCodester Lost and Found Information System HTTP POST Request sql injection
Published 2023-07-23 · Modified
9.8EPSS 0.005
CVE-2024-37857
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.
Published 2024-07-29 · Modified
8.8EPSS 0.008
CVE-2023-2670
SourceCodester Lost and Found Information System access control
Published 2023-05-12 · Modified
8.8EPSS 0.008
CVE-2023-3018
SourceCodester Lost and Found Information System access control
Published 2023-05-31 · Modified
8.8EPSS 0.007
CVE-2023-3176
SourceCodester Lost and Found Information System manage_user.php sql injection
Published 2023-06-09 · Modified
8.8EPSS 0.007
CVE-2023-3177
SourceCodester Lost and Found Information System view_inquiry.php sql injection
Published 2023-06-09 · Modified
8.8EPSS 0.007
CVE-2023-33676
Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.
Published 2024-03-07 · Analyzed
8.4EPSS 0.007
CVE-2023-33677
Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".
Published 2024-03-06 · Modified
7.5EPSS 0.004
CVE-2023-2667
SourceCodester Lost and Found Information System cross site scripting
Published 2023-05-12 · Modified
6.1EPSS 0.007
CVE-2023-36159
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
Published 2023-08-03 · Modified
6.1EPSS 0.006
CVE-2023-2671
SourceCodester Lost and Found Information System Contact Form cross site scripting
Published 2023-05-12 · Modified
6.1EPSS 0.006
CVE-2024-37859
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.
Published 2024-07-29 · Modified
6.1EPSS 0.004
CVE-2023-3017
SourceCodester Lost and Found Information System Manage User Page cross site scripting
Published 2023-05-31 · Modified
5.4EPSS 0.005
CVE-2024-37856
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.
Published 2024-07-29 · Modified
5.4EPSS 0.003