Vendorsoretnom23packers_and_movers_management_system1.0
Vulnerabilities

oretnom23 Packers And Movers Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-30415
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.
Published 2023-09-28 · Modified
9.8EPSS 0.010
CVE-2023-46435
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.
Published 2023-10-26 · Modified
9.8EPSS 0.006
CVE-2024-48427
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
Published 2024-10-24 · Analyzed
8.8EPSS 0.009
CVE-2023-46956
SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.
Published 2023-11-30 · Modified
7.2EPSS 0.012
CVE-2024-57522
SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.
Published 2025-02-03 · Analyzed
6.4EPSS 0.010
CVE-2024-57523
Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.
Published 2025-02-06 · Modified
4.5EPSS 0.005