CVE-2024-11073 – SourceCodester Hospital Management System delete-account.php improper authorization
https://notcve.org/view.php?id=CVE-2024-11073
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /vm/patient/delete-account.php. The manipulation of the argument id leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://drive.google.com/file/d/1yFo0re8taTry7oR4-EDg3UHwO2lkqO9N/view?usp=sharing https://github.com/Salah-Tayeh/CVEs-and-Vulnerabilities/blob/main/Hospital%20Management%20System%20-%20IDOR%20Causing%20Deletion%20of%20any%20patient%20account.md https://vuldb.com/?ctiid.283869 https://vuldb.com/?id.283869 https://vuldb.com/?submit.440799 https://www.sourcecodester.com • CWE-266: Incorrect Privilege Assignment CWE-285: Improper Authorization •
CVE-2024-11054 – SourceCodester Simple Music Cloud Community System ajax.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-11054
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. • https://vuldb.com/?ctiid.283798 https://vuldb.com/?id.283798 https://vuldb.com/?submit.438756 https://www.shawroot.cc/2826.html https://www.sourcecodester.com • CWE-284: Improper Access Control CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-10990 – SourceCodester Online Veterinary Appointment System view_service.php sql injection
https://notcve.org/view.php?id=CVE-2024-10990
A vulnerability classified as critical was found in SourceCodester Online Veterinary Appointment System 1.0. This vulnerability affects unknown code of the file /admin/services/view_service.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/AspirePig/Cve_report/blob/main/online-veterinary-appointment-system/SQLi-1.md https://vuldb.com/?ctiid.283456 https://vuldb.com/?id.283456 https://vuldb.com/?submit.437383 https://www.sourcecodester.com • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-10559 – SourceCodester Airport Booking Management System Passport Number details buffer overflow
https://notcve.org/view.php?id=CVE-2024-10559
A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function details of the component Passport Number Handler. The manipulation leads to buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. • https://github.com/CveSecLook/cve/issues/64 https://vuldb.com/?ctiid.282560 https://vuldb.com/?id.282560 https://vuldb.com/?submit.433262 https://www.sourcecodester.com • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2024-10450 – SourceCodester Kortex Lite Advocate Office Management System POST Parameter edit_profile.php sql injection
https://notcve.org/view.php?id=CVE-2024-10450
A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /kortex_lite/control/edit_profile.php of the component POST Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/will121351/wenqin.webray.com.cn/blob/main/CVE-project/Advocate-office-management-system.md https://vuldb.com/?ctiid.282010 https://vuldb.com/?id.282010 https://vuldb.com/?submit.432614 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •