VendorsWeb-based Student Clearance System Projectweb-based_student_clearance_systemall versions
Vulnerabilities

Web-based Student Clearance System Project Web-based Student Clearance System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-3414
SourceCodester Web-Based Student Clearance System POST Parameter login.php sql injection
Published 2022-10-07 · Modified
9.8EPSS 0.006
CVE-2022-3733
SourceCodester Web-Based Student Clearance System edit-admin.php sql injection
Published 2022-10-28 · Modified
8.8EPSS 0.006
CVE-2022-3436
SourceCodester Web-Based Student Clearance System Photo edit-photo.php unrestricted upload
Published 2022-10-09 · Modified
7.5EPSS 0.005
CVE-2022-3434
SourceCodester Web-Based Student Clearance System add-student.php prepare cross site scripting
Published 2022-10-08 · Modified
5.4EPSS 0.006
CVE-2022-43076
A cross-site scripting (XSS) vulnerability in /admin/edit-admin.php of Web-Based Student Clearance System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtemail parameter.
Published 2022-11-01 · Modified
4.8EPSS 0.005
CVE-2022-43078
A cross-site scripting (XSS) vulnerability in /admin/add-fee.php of Web-Based Student Clearance System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.
Published 2022-11-01 · Modified
4.8EPSS 0.005
CVE-2022-45223
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.
Published 2022-11-28 · Modified
4.8EPSS 0.005
CVE-2022-45224
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.
Published 2022-11-28 · Modified
4.8EPSS 0.005
CVE-2022-45221
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtnew_password parameter.
Published 2022-11-28 · Modified
4.8EPSS 0.005