Vendorsoretnom23school_fees_management_systemall versions
Vulnerabilities

oretnom23 School Fees Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-49982
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.
Published 2024-03-06 · Analyzed
8.8EPSS 0.008
CVE-2023-49981
A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.
Published 2024-03-06 · Analyzed
7.5EPSS 0.007
CVE-2023-49983
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
Published 2024-03-06 · Analyzed
6.8EPSS 0.006
CVE-2023-49985
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.
Published 2024-03-06 · Analyzed
6.5EPSS 0.005
CVE-2023-49984
A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
Published 2024-03-06 · Analyzed
6.1EPSS 0.005
CVE-2023-49987
A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.
Published 2024-03-07 · Analyzed
5.4EPSS 0.004
CVE-2023-49986
A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
Published 2024-03-07 · Analyzed
4.7EPSS 0.005