VendorsSLiMSsenayan_library_management_systemall versions
Vulnerabilities

SLiMS Senayan Library Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2023-3744
Server-Side Request Forgery in SLiMS
Published 2023-10-02 · Modified
9.9EPSS 0.005
CVE-2022-38292
SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.
Published 2022-09-12 · Modified
9.8EPSS 0.009
CVE-2023-45996
SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.
Published 2023-10-31 · Modified
8.8EPSS 0.011
CVE-2021-45791
Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated librarian users.
Published 2022-03-17 · Modified
8.8EPSS 0.010
CVE-2017-12584
There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2 fields in an admin/modules/system/app_user.php changecurrent=true operation.
Published 2017-08-06 · Modified
8.8EPSS 0.009
CVE-2023-40970
Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.
Published 2023-09-01 · Modified
8.8EPSS 0.007
CVE-2021-45793
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
Published 2022-03-17 · Modified
7.5EPSS 0.045
CVE-2021-45794
Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.
Published 2022-03-17 · Modified
7.5EPSS 0.011
CVE-2022-45019
SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.
Published 2022-12-05 · Modified
7.5EPSS 0.008
CVE-2023-29850
SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
Published 2023-04-14 · Modified
7.5EPSS 0.007
CVE-2022-43362
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.
Published 2022-11-01 · Modified
7.2EPSS 0.008
CVE-2025-26200
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
Published 2025-02-24 · Analyzed
7.2EPSS 0.005
CVE-2022-38291
SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.
Published 2022-09-12 · Modified
6.1EPSS 0.005
CVE-2023-40969
Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php.
Published 2023-09-01 · Modified
6.1EPSS 0.004
CVE-2024-25288
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
Published 2024-02-21 · Analyzed
4.9EPSS 0.005
CVE-2021-45792
Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.
Published 2022-03-17 · Modified
4.8EPSS 0.005
CVE-2022-43361
Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.
Published 2022-11-01 · Modified
4.8EPSS 0.004