CVE-2023-2823 – SourceCodester Class Scheduling System GET Parameter edit_subject.php sql injection
https://notcve.org/view.php?id=CVE-2023-2823
A vulnerability was found in SourceCodester Class Scheduling System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit_subject.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. • https://github.com/zhulielie/CVEReport/blob/main/SQL.md https://vuldb.com/?ctiid.229597 https://vuldb.com/?id.229597 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2814 – SourceCodester Class Scheduling System POST Parameter save_teacher.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-2814
A vulnerability classified as problematic has been found in SourceCodester Class Scheduling System 1.0. Affected is an unknown function of the file /admin/save_teacher.php of the component POST Parameter Handler. The manipulation of the argument Academic_Rank leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/jiy2020/bugReport/blob/main/XSS.md https://vuldb.com/?ctiid.229428 https://vuldb.com/?id.229428 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •