Vendorsoretnom23simple_customer_relationship_management_systemall versions
Vulnerabilities

oretnom23 Simple Customer Relationship Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2023-24655
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
Published 2023-03-23 · Modified
9.8EPSS 0.010
CVE-2023-0917
SourceCodester Simple Customer Relationship Management System login.php sql injection
Published 2023-02-19 · Analyzed
9.8EPSS 0.009
CVE-2023-24729
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
Published 2023-03-15 · Modified
8.8EPSS 0.010
CVE-2023-24730
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.
Published 2023-03-15 · Modified
8.8EPSS 0.010
CVE-2023-24364
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.
Published 2023-02-27 · Modified
8.8EPSS 0.010
CVE-2023-24652
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.
Published 2023-02-27 · Modified
8.8EPSS 0.010
CVE-2023-24653
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.
Published 2023-02-27 · Modified
8.8EPSS 0.010
CVE-2023-24654
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.
Published 2023-02-27 · Modified
8.8EPSS 0.010
CVE-2023-24656
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function.
Published 2023-02-27 · Modified
8.8EPSS 0.010
CVE-2023-24728
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
Published 2023-03-15 · Modified
8.8EPSS 0.010
CVE-2023-24731
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.
Published 2023-03-15 · Modified
8.8EPSS 0.010
CVE-2023-24732
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.
Published 2023-03-15 · Modified
8.8EPSS 0.010
CVE-2023-24204
SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.
Published 2024-05-14 · Analyzed
5.4EPSS 0.006
CVE-2023-24203
Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).
Published 2024-05-14 · Analyzed
5.4EPSS 0.006
CVE-2023-24651
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.
Published 2023-02-27 · Modified
5.4EPSS 0.006