CVE-2024-8346 – SourceCodester Computer Laboratory Management System SystemSettings.php update_settings_info sql injection
https://notcve.org/view.php?id=CVE-2024-8346
A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. • https://github.com/gaorenyusi/gaorenyusi/blob/main/lms1.md https://vuldb.com/?ctiid.276228 https://vuldb.com/?id.276228 https://vuldb.com/?submit.400343 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-8345 – SourceCodester Music Gallery Site Users.php sql injection
https://notcve.org/view.php?id=CVE-2024-8345
A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. • https://github.com/GAO-UNO/cve/blob/main/sql3.md https://vuldb.com/?ctiid.276224 https://vuldb.com/?id.276224 https://vuldb.com/?submit.400192 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-8343 – SourceCodester Sentiment Based Movie Rating System User Registration Users.php sql injection
https://notcve.org/view.php?id=CVE-2024-8343
A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. • https://github.com/gurudattch/CVEs/blob/main/Sourcecodester-SQLi-Sentiment-Based-Moive-Rating.md https://vuldb.com/?ctiid.276222 https://vuldb.com/?id.276222 https://vuldb.com/?submit.399711 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-8342 – SourceCodester Petshop Management System add_client.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-8342
A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This issue affects some unknown processing of the file /controllers/add_client.php. The manipulation of the argument image_profile leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Petshop_Management_System/Petshop_Management_System%20add_client.php%20any%20file%20upload.md https://vuldb.com/?ctiid.276221 https://vuldb.com/?id.276221 https://vuldb.com/?submit.399662 https://www.sourcecodester.com • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-8341 – SourceCodester Petshop Management System add_user.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-8341
A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability affects unknown code of the file /controllers/add_user.php. The manipulation of the argument avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Petshop_Management_System/Petshop_Management_System%20add_user.php%20any%20file%20upload.md https://vuldb.com/?ctiid.276220 https://vuldb.com/?id.276220 https://vuldb.com/?submit.399661 https://www.sourcecodester.com • CWE-434: Unrestricted Upload of File with Dangerous Type •