CVE-2024-7644 – SourceCodester Leads Manager Tool Add Leads add-leads.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-7644
A vulnerability was found in SourceCodester Leads Manager Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-leads.php of the component Add Leads Handler. The manipulation of the argument leads_name/phone_number leads to cross site scripting. It is possible to initiate the attack remotely. • https://github.com/joinia/webray.com.cn/blob/main/Leads-Manager-Tool/leadmanagerxss.md https://vuldb.com/?ctiid.274065 https://vuldb.com/?id.274065 https://vuldb.com/?submit.387345 https://www.sourcecodester.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-7643 – SourceCodester Leads Manager Tool Delete Leads delete-leads.php sql injection
https://notcve.org/view.php?id=CVE-2024-7643
A vulnerability was found in SourceCodester Leads Manager Tool 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/delete-leads.php of the component Delete Leads Handler. The manipulation of the argument leads leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/joinia/webray.com.cn/blob/main/Leads-Manager-Tool/leadmanagersql.md https://vuldb.com/?ctiid.274064 https://vuldb.com/?id.274064 https://vuldb.com/?submit.387344 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-7642 – SourceCodester Kortex Lite Advocate Office Management System activate_act.php sql injection
https://notcve.org/view.php?id=CVE-2024-7642
A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file activate_act.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/samwbs/kortexcve/blob/main/sqli_activate_act/sqli_activate_act.md https://vuldb.com/?ctiid.274063 https://vuldb.com/?id.274063 https://vuldb.com/?submit.387276 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-7641 – SourceCodester Kortex Lite Advocate Office Management System deactivate_act.php sql injection
https://notcve.org/view.php?id=CVE-2024-7641
A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file deactivate_act.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/samwbs/kortexcve/blob/main/sqli_deactivate_act/sqli_deactivate_act.md https://vuldb.com/?ctiid.274062 https://vuldb.com/?id.274062 https://vuldb.com/?submit.387273 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-7640 – SourceCodester Kortex Lite Advocate Office Management System delete_register.php sql injection
https://notcve.org/view.php?id=CVE-2024-7640
A vulnerability, which was classified as critical, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This issue affects some unknown processing of the file delete_register.php. The manipulation of the argument case_register_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/samwbs/kortexcve/blob/main/sqli_delete_register/sqli_delete_register.md https://vuldb.com/?ctiid.274061 https://vuldb.com/?id.274061 https://vuldb.com/?submit.387272 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •