CVE-2022-30404
https://notcve.org/view.php?id=CVE-2022-30404
College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=. College Management System versión v1.0, es vulnerable a una inyección SQL por medio de /College_Management_System/admin/display-teacher.php?teacher_id= • https://github.com/k0xx11/bug_report/blob/main/vendors/code-projects/College-Management-System/SQLi-1.md. • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-28079 – College Management System 1.0 - 'course_code' SQL Injection (Authenticated)
https://notcve.org/view.php?id=CVE-2022-28079
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. Se ha detectado que College Management System versión v1.0, contiene una vulnerabilidad de inyección SQL por medio del parámetro course_code College Management System version 1.0 suffers from a remote SQL injection vulnerability. • https://www.exploit-db.com/exploits/50933 http://packetstormsecurity.com/files/167131/College-Management-System-1.0-SQL-Injection.html https://code-projects.org/college-management-system-in-php-with-source-code https://github.com/erengozaydin/College-Management-System-course_code-SQL-Injection-Authenticated https://www.nu11secur1ty.com/2022/05/cve-2022-28079.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-26615
https://notcve.org/view.php?id=CVE-2022-26615
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields. Una vulnerabilidad de tipo cross-site scripting (XSS) en College Website Content Management System versión v1.0, permite a atacantes ejecutar scripts web o HTML arbitrarios por medio de una carga útil diseñada inyectada en los campos de texto de User Profile Name • https://github.com/nsparker1337/OpenSource/blob/main/exploit_xss_cwms • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-1078 – SourceCodester College Website Management System sql injection
https://notcve.org/view.php?id=CVE-2022-1078
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. • https://vuldb.com/?id.194856 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-1075 – College Website Management System Contact cross site scripting
https://notcve.org/view.php?id=CVE-2022-1075
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication. • https://vuldb.com/?id.194846 https://www.sourcecodester.com/php/15203/college-website-content-management-system-phpoop-free-source-code.ht • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •