
CVE-2024-8610 – SourceCodester Best House Rental Management System New Tenant Page index.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8610
09 Sep 2024 — A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants of the component New Tenant Page. The manipulation of the argument Last Name/First Name/Middle Name leads to cross site scripting. It is possible to launch the attack remotely. • https://drive.google.com/file/d/1mB2ZNyWJDqJaZZro4qiMqovRO_qo4pss/view?usp=sharing • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-8604 – SourceCodester Online Food Ordering System Create an Account Page index.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8604
09 Sep 2024 — A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. Es wurde eine Schwachstelle in SourceCodester Online Food Ordering System 2.0 entdeckt. • https://vuldb.com/?id.276831 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-8583 – SourceCodester Online Bank Management System Feedback mfeedback.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8583
08 Sep 2024 — A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects an unknown part of the file /mfeedback.php of the component Feedback Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. • https://github.com/Niu-zida/cve/blob/main/Storage-optimized%20Cross-site%20scripting%20vulnerability.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-8582 – SourceCodester Food Ordering Management System index.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8582
08 Sep 2024 — A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument description leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Niu-zida/cve/blob/main/Cross-Site%20Scripting.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-8564 – SourceCodester PHP CRUD update.php sql injection
https://notcve.org/view.php?id=CVE-2024-8564
07 Sep 2024 — A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The manipulation of the argument tbl_person_id/first_name/middle_name/last_name leads to sql injection. The attack can be initiated remotely. • https://vuldb.com/?ctiid.276784 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-8563 – SourceCodester PHP CRUD update.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8563
07 Sep 2024 — A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. It is possible to initiate the attack remotely. • https://vuldb.com/?ctiid.276783 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-8562 – SourceCodester PHP CRUD Add.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-8562
07 Sep 2024 — A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.276782 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-8561 – SourceCodester PHP CRUD Delete Person delete.php sql injection
https://notcve.org/view.php?id=CVE-2024-8561
07 Sep 2024 — A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation of the argument person leads to sql injection. The attack can be launched remotely. In SourceCodester PHP CRUD 1.0 wurde eine Schwachstelle gefunden. • https://vuldb.com/?ctiid.276781 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-8560 – SourceCodester Simple Invoice Generator System save_invoice.php sql injection
https://notcve.org/view.php?id=CVE-2024-8560
07 Sep 2024 — A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.276780 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-8559 – SourceCodester Online Food Menu delete-menu.php sql injection
https://notcve.org/view.php?id=CVE-2024-8559
07 Sep 2024 — A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.276779 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •