CVE-2022-45221
https://notcve.org/view.php?id=CVE-2022-45221
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtnew_password parameter. Se descubrió que Web-Based Student Clearance System v1.0 contiene una vulnerabilidad de Cross-Site Scripting (XSS) en changepassword.php. Esta vulnerabilidad permite a los atacantes ejecutar scripts web o HTML arbitrarios a través de un payload manipulado inyectado en el parámetro txtnew_password. • https://medium.com/%40just0rg/web-based-student-clearance-system-in-php-free-source-code-v1-0-unrestricted-input-leads-to-xss-5802ead12124 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-45223
https://notcve.org/view.php?id=CVE-2022-45223
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter. Se descubrió que Web-Based Student Clearance System v1.0 contiene una vulnerabilidad de Cross-Site Scripting (XSS) en /Admin/add-student.php. Esta vulnerabilidad permite a los atacantes ejecutar scripts web o HTML arbitrarios a través de un payload manipulado inyectado en el parámetro txtfullname. • https://medium.com/%40just0rg/web-based-student-clearance-system-in-php-free-source-code-v1-0-unrestricted-input-leads-to-xss-5802ead12124 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-45224
https://notcve.org/view.php?id=CVE-2022-45224
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter. Se descubrió que Web-Based Student Clearance System v1.0 contiene una vulnerabilidad de Cross-Site Scripting (XSS) en Admin/add-admin.php. Esta vulnerabilidad permite a los atacantes ejecutar scripts web o HTML arbitrarios a través de un payload manipulado inyectado en el parámetro txtfullname. • https://medium.com/%40just0rg/book-store-management-system-1-0-unrestricted-input-leads-to-xss-74506d42492e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-43076
https://notcve.org/view.php?id=CVE-2022-43076
A cross-site scripting (XSS) vulnerability in /admin/edit-admin.php of Web-Based Student Clearance System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtemail parameter. Una vulnerabilidad de Cross-Site Scripting (XSS) en /admin/edit-admin.php del Web-Based Student Clearance System v1.0 permite a los atacantes ejecutar scripts web o HTML arbitrarios a través de un payload manipulado inyectado en el parámetro txtemail. • https://github.com/Tr0e/CVE_Hunter/blob/main/XSS-1.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-43078
https://notcve.org/view.php?id=CVE-2022-43078
A cross-site scripting (XSS) vulnerability in /admin/add-fee.php of Web-Based Student Clearance System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter. Una vulnerabilidad de Cross-Site Scripting (XSS) en /admin/add-fee.php del Web-Based Student Clearance System v1.0 permite a los atacantes ejecutar scripts web arbitrarias o HTML a través de un payload manipulado inyectado en el parámetro cmddept. • https://github.com/Tr0e/CVE_Hunter/blob/main/XSS-2.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •