Vendorsoretnom23simple_cold_storage_management_systemall versions
Vulnerabilities

oretnom23 Simple Cold Storage Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2021-45435
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.
Published 2022-01-28 · Modified
9.8EPSS 0.011
CVE-2022-42232
Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=delete_storage.
Published 2022-10-14 · Modified
7.2EPSS 0.009
CVE-2022-42241
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.
Published 2022-10-06 · Modified
7.2EPSS 0.009
CVE-2022-42242
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.
Published 2022-10-06 · Modified
7.2EPSS 0.009
CVE-2022-42243
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id=.
Published 2022-10-06 · Modified
7.2EPSS 0.009
CVE-2022-42249
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
Published 2022-10-06 · Modified
7.2EPSS 0.009
CVE-2022-42250
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=.
Published 2022-10-06 · Modified
7.2EPSS 0.009
CVE-2022-3549
SourceCodester Simple Cold Storage Management System Avatar unrestricted upload
Published 2022-10-17 · Modified
7.2EPSS 0.006
CVE-2022-3587
SourceCodester Simple Cold Storage Management System My Account cross site scripting
Published 2022-10-18 · Modified
5.4EPSS 0.005
CVE-2022-3546
SourceCodester Simple Cold Storage Management System Create User cross site scripting
Published 2022-10-17 · Modified
4.8EPSS 0.006
CVE-2022-3548
SourceCodester Simple Cold Storage Management System Add New Storage cross site scripting
Published 2022-10-17 · Modified
4.8EPSS 0.006
CVE-2022-3585
SourceCodester Simple Cold Storage Management System Contact Us cross-site request forgery
Published 2022-10-18 · Modified
4.3EPSS 0.003
CVE-2022-3582
SourceCodester Simple Cold Storage Management System cross-site request forgery
Published 2022-10-18 · Modified
4.3EPSS 0.003