CVE-2023-3119 – SourceCodester Service Provider Management System view.php sql injection
https://notcve.org/view.php?id=CVE-2023-3119
A vulnerability, which was classified as critical, has been found in SourceCodester Service Provider Management System 1.0. Affected by this issue is some unknown functionality of the file view.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Peanut886/Vulnerability/blob/main/webray.com.cn/Service%20Provider%20Management%20System%20-%20multiple%20vulnerabilities.md https://vuldb.com/?ctiid.230798 https://vuldb.com/?id.230798 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-3018 – SourceCodester Lost and Found Information System access control
https://notcve.org/view.php?id=CVE-2023-3018
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/?page=user/list. The manipulation leads to improper access controls. • https://medium.com/@akashpandey380/lost-and-found-information-system-v1-0-idor-cve-2023-977966c4450d https://vuldb.com/?ctiid.230362 https://vuldb.com/?id.230362 • CWE-284: Improper Access Control •
CVE-2023-3017 – SourceCodester Lost and Found Information System Manage User Page cross site scripting
https://notcve.org/view.php?id=CVE-2023-3017
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been classified as problematic. This affects an unknown part of the file admin/?page=user/manage_user of the component Manage User Page. The manipulation of the argument First Name/Middle Name/Last Name leads to basic cross site scripting. • https://medium.com/@akashpandey380/lost-and-found-information-system-v1-0-html-injection-3596f2b856c0 https://vuldb.com/?ctiid.230361 https://vuldb.com/?id.230361 • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •
CVE-2023-2772 – SourceCodester Budget and Expense Tracker System GET Parameter manage_budget.php sql injection
https://notcve.org/view.php?id=CVE-2023-2772
A vulnerability, which was classified as critical, was found in SourceCodester Budget and Expense Tracker System 1.0. Affected is an unknown function of the file /admin/budget/manage_budget.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/wucwu1/CVEApplication/blob/main/SQL.md https://vuldb.com/?ctiid.229278 https://vuldb.com/?id.229278 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2769 – SourceCodester Service Provider Management System sql injection
https://notcve.org/view.php?id=CVE-2023-2769
A vulnerability classified as critical has been found in SourceCodester Service Provider Management System 1.0. This affects an unknown part of the file /classes/Master.php?f=delete_service. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/Serviced-Providerd-Managementd-Systemd--d-SQLd-injections.md https://vuldb.com/?ctiid.229275 https://vuldb.com/?id.229275 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •