
CVE-2023-44824
https://notcve.org/view.php?id=CVE-2023-44824
17 Oct 2023 — An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component. Un problema en Expense Management System v.1.0 permite a un atacante local ejecutar código arbitrario a través de un archivo manipulado subido al componente sign-up.php. • https://abstracted-howler-727.notion.site/CVE-2023-44824-ab76909b4a0e477b87aa8d0ca4aa4ca7 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2023-5585 – SourceCodester Online Motorcycle Rental System Bike List cross site scripting
https://notcve.org/view.php?id=CVE-2023-5585
14 Oct 2023 — A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/?page=bike of the component Bike List. The manipulation of the argument Model with the input "><script>confirm (document.cookie)</script> leads to cross site scripting. • https://vuldb.com/?ctiid.242170 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-5581 – SourceCodester Medicine Tracker System index.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-5581
14 Oct 2023 — A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument page leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/GodRone/MedicineTrackerSystem/blob/main/Medicine%20Tracker%20System_XSS.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-38965 – Lost and Found Information System 1.0 Insecure Direct Object Reference
https://notcve.org/view.php?id=CVE-2023-38965
12 Oct 2023 — Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI. Lost and Found Information System 1.0 permite la toma de control de cuentas mediante nombre de usuario y contraseña en un /classes/Users.php?f=save URI. Lost and Found Information System version 1.0 suffers from an insecure direct object reference vulnerability that allows for account takeover. • https://packetstorm.news/files/id/175077 • CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2023-5423 – SourceCodester Online Pizza Ordering System sql injection
https://notcve.org/view.php?id=CVE-2023-5423
05 Oct 2023 — A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. • https://vuldb.com/?ctiid.241384 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-5374 – SourceCodester Online Computer and Laptop Store products.php sql injection
https://notcve.org/view.php?id=CVE-2023-5374
04 Oct 2023 — A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. The manipulation of the argument c leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/llixixi/Engineers-Online-Portal-System/blob/main/Computer%20and%20Laptop%20Store%20System%20products.php%20has%20Sqlinjection.pdf • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-5373 – SourceCodester Online Computer and Laptop Store Master.php register sql injection
https://notcve.org/view.php?id=CVE-2023-5373
04 Oct 2023 — A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is the function register of the file Master.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Szlllc/Cve/blob/main/Computer%20and%20Laptop%20Store%20System%20Master.php%20has%20Sqlinjection.pdf • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-5286 – SourceCodester Expense Tracker App Category add_category.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-5286
29 Sep 2023 — A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected by this issue is some unknown functionality of the file add_category.php of the component Category Handler. The manipulation of the argument category_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/xcodeOn1/XSS-Stored-Expense-Tracker-App • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-44048
https://notcve.org/view.php?id=CVE-2023-44048
27 Sep 2023 — Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category. La aplicación Sourcecodester Expense Tracker v1 es vulnerable a Cross Site Scripting (XSS) a través de la categoría "add". • https://github.com/xcodeOn1/XSS-Stored-Expense-Tracker-App/tree/main • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43456
https://notcve.org/view.php?id=CVE-2023-43456
25 Sep 2023 — Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint. Una vulnerabilidad de cross site scripting en Service Provider Management System v.1.0 permite a un atacante remoto ejecutar código arbitrario y obtener información sensible a través de los parámetros de nombre, segundo nombre y apellido en el endpoin... • https://samh4cks.github.io/posts/cve-2023-43456 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •