Vendorsoretnom23simple_student_attendance_systemall versions
Vulnerabilities

oretnom23 Simple Student Attendance System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2023-51801
SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.
Published 2024-02-29 · Analyzed
9.8EPSS 0.012
CVE-2023-6657
SourceCodester Simple Student Attendance System student_form.php sql injection
Published 2023-12-10 · Modified
9.8EPSS 0.009
CVE-2024-1923
SourceCodester Simple Student Attendance System List of Classes Page ajax-api.php delete_student sql injection
Published 2024-02-27 · Analyzed
9.8EPSS 0.008
CVE-2023-6658
SourceCodester Simple Student Attendance System sql injection
Published 2023-12-10 · Modified
9.8EPSS 0.008
CVE-2023-6617
SourceCodester Simple Student Attendance System attendance.php sql injection
Published 2023-12-08 · Modified
9.8EPSS 0.008
CVE-2023-6619
SourceCodester Simple Student Attendance System class_form.php sql injection
Published 2023-12-08 · Modified
9.8EPSS 0.008
CVE-2023-7058
SourceCodester Simple Student Attendance System path traversal
Published 2023-12-22 · Modified
9.8EPSS 0.007
CVE-2023-6771
SourceCodester Simple Student Attendance System actions.class.php save_attendance sql injection
Published 2023-12-13 · Modified
9.8EPSS 0.006
CVE-2023-6618
SourceCodester Simple Student Attendance System index.php file inclusion
Published 2023-12-08 · Modified
8.8EPSS 0.009
CVE-2023-51802
Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the page or class_month parameter in the /php-attendance/attendance_report component.
Published 2024-02-29 · Analyzed
6.1EPSS 0.006
CVE-2023-6616
SourceCodester Simple Student Attendance System index.php cross site scripting
Published 2023-12-08 · Modified
6.1EPSS 0.006
CVE-2024-1834
SourceCodester Simple Student Attendance System ?page=attendance&class_id=1 cross site scripting
Published 2024-02-23 · Analyzed
6.1EPSS 0.006
CVE-2024-6212
SourceCodester Simple Student Attendance System student_form.php get_student cross site scripting
Published 2024-06-21 · Modified
6.1EPSS 0.005
CVE-2024-25551
Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.
Published 2024-03-03 · Analyzed
6.1EPSS 0.004