
CVE-2022-26615
https://notcve.org/view.php?id=CVE-2022-26615
05 Apr 2022 — A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields. Una vulnerabilidad de tipo cross-site scripting (XSS) en College Website Content Management System versión v1.0, permite a atacantes ejecutar scripts web o HTML arbitrarios por medio de una carga útil diseñada inyectada en los campos de texto de User Profile Name • https://github.com/nsparker1337/OpenSource/blob/main/exploit_xss_cwms • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-1078 – SourceCodester College Website Management System sql injection
https://notcve.org/view.php?id=CVE-2022-1078
29 Mar 2022 — A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. • https://vuldb.com/?id.194856 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-1075 – College Website Management System Contact cross site scripting
https://notcve.org/view.php?id=CVE-2022-1075
29 Mar 2022 — A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication. • https://vuldb.com/?id.194846 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-25408
https://notcve.org/view.php?id=CVE-2020-25408
24 May 2021 — A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data. Se presenta una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en ProjectWorlds College Management System Php versión 1.0, que permite a un atacante remoto modificar, eliminar o realizar una nueva entrada de datos de estudiantes, profesores, asig... • https://github.com/olotieno/College-Management-System-Php • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2020-25409
https://notcve.org/view.php?id=CVE-2020-25409
24 May 2021 — Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. Projectsworlds College Management System Php versión 1.0, es vulnerable a problemas de inyección SQL en parámetros múltiples • https://github.com/olotieno/College-Management-System-Php/tree/master/College-Management-System%20in%20Php_5.5/College-Management-System%20in%20Php_5.5 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2020-26051
https://notcve.org/view.php?id=CVE-2020-26051
08 Feb 2021 — College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query. College Management System Php versión 1.0, sufre de vulnerabilidades de inyección SQL en la página index.php de los parámetros POST "unametxt" y "pwdtxt", que no son filtradas antes de pasar una consulta SQL • https://www.exploit-db.com/exploits/48593 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •