VendorsSchool Event Management System Projectschool_event_management_systemall versions
Vulnerabilities

School Event Management System Project School Event Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
Published 2018-11-16 · Modified
9.81 PoCEPSS 0.095
CVE-2018-18795
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
Published 2018-11-16 · Modified
9.81 PoCEPSS 0.032
CVE-2018-18794
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
Published 2018-11-16 · Modified
8.81 PoCEPSS 0.024