CVE-2022-26615
https://notcve.org/view.php?id=CVE-2022-26615
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields. Una vulnerabilidad de tipo cross-site scripting (XSS) en College Website Content Management System versión v1.0, permite a atacantes ejecutar scripts web o HTML arbitrarios por medio de una carga útil diseñada inyectada en los campos de texto de User Profile Name • https://github.com/nsparker1337/OpenSource/blob/main/exploit_xss_cwms • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1078 – SourceCodester College Website Management System sql injection
https://notcve.org/view.php?id=CVE-2022-1078
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. • https://vuldb.com/?id.194856 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-1075 – College Website Management System Contact cross site scripting
https://notcve.org/view.php?id=CVE-2022-1075
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication. • https://vuldb.com/?id.194846 https://www.sourcecodester.com/php/15203/college-website-content-management-system-phpoop-free-source-code.ht • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-25408
https://notcve.org/view.php?id=CVE-2020-25408
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data. Se presenta una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en ProjectWorlds College Management System Php versión 1.0, que permite a un atacante remoto modificar, eliminar o realizar una nueva entrada de datos de estudiantes, profesores, asignaturas, puntuaciones, ubicación y artículos • https://github.com/olotieno/College-Management-System-Php https://nikhilkumar01.medium.com/cve-2020-25408-97eb7bcc23a6 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-25409
https://notcve.org/view.php?id=CVE-2020-25409
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. Projectsworlds College Management System Php versión 1.0, es vulnerable a problemas de inyección SQL en parámetros múltiples • https://github.com/olotieno/College-Management-System-Php/tree/master/College-Management-System%20in%20Php_5.5/College-Management-System%20in%20Php_5.5 https://nikhilkumar01.medium.com/cve-2020-25409-5ecbe735c004 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •