Vendorsrazormistloan_management_systemall versions
Vulnerabilities

razormist Loan Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-2766
SourceCodester Loan Management System index.php sql injection
Published 2022-08-11 · Modified
9.8EPSS 0.012
CVE-2022-37138
Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.
Published 2022-09-14 · Modified
9.8EPSS 0.012
CVE-2022-2666
SourceCodester Loan Management System login.php sql injection
Published 2023-01-07 · Modified
9.8EPSS 0.009
CVE-2024-31678
Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.
Published 2024-04-11 · Analyzed
9.8EPSS 0.006
CVE-2022-2667
SourceCodester Loan Management System delete_lplan.php sql injection
Published 2022-08-05 · Modified
8.8EPSS 0.009
CVE-2023-6310
SourceCodester Loan Management System deleteBorrower.php delete_borrower sql injection
Published 2023-11-27 · Modified
7.2EPSS 0.008
CVE-2023-6311
SourceCodester Loan Management System Loan Type Page delete_ltype.php delete_ltype sql injection
Published 2023-11-27 · Modified
7.2EPSS 0.008
CVE-2023-6312
SourceCodester Loan Management System Users Page deleteUser.php delete_user sql injection
Published 2023-11-27 · Modified
7.2EPSS 0.008
CVE-2022-37139
Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
Published 2022-09-14 · Modified
5.4EPSS 0.006
CVE-2023-27242
SourceCodester Loan Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Type parameter under the Edit Loan Types module.
Published 2023-03-24 · Modified
5.4EPSS 0.004
CVE-2024-48415
itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.
Published 2024-10-22 · Analyzed
5.0EPSS 0.004