
CVE-2025-0800 – SourceCodester Online Courseware Edit Teacher saveeditt.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-0800
29 Jan 2025 — A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.293922 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2024-3428 – SourceCodester Online Courseware edit.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-3428
07 Apr 2024 — A vulnerability has been found in SourceCodester Online Courseware 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-13.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-3427 – SourceCodester Online Courseware addq.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-3427
07 Apr 2024 — A vulnerability, which was classified as problematic, was found in SourceCodester Online Courseware 1.0. This affects an unknown part of the file addq.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-12.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-3426 – SourceCodester Online Courseware editt.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-3426
07 Apr 2024 — A vulnerability, which was classified as problematic, has been found in SourceCodester Online Courseware 1.0. Affected by this issue is some unknown functionality of the file editt.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-11.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-3425 – SourceCodester Online Courseware activateall.php sql injection
https://notcve.org/view.php?id=CVE-2024-3425
07 Apr 2024 — A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. Affected by this vulnerability is an unknown functionality of the file admin/activateall.php. The manipulation of the argument selector leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-10.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3424 – SourceCodester Online Courseware listscore.php sql injection
https://notcve.org/view.php?id=CVE-2024-3424
07 Apr 2024 — A vulnerability classified as critical has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file admin/listscore.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-09.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3423 – SourceCodester Online Courseware activateteach.php sql injection
https://notcve.org/view.php?id=CVE-2024-3423
07 Apr 2024 — A vulnerability was found in SourceCodester Online Courseware 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/activateteach.php. The manipulation of the argument selector leads to sql injection. The attack may be initiated remotely. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-08.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3422 – SourceCodester Online Courseware activatestud.php sql injection
https://notcve.org/view.php?id=CVE-2024-3422
07 Apr 2024 — A vulnerability was found in SourceCodester Online Courseware 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/activatestud.php. The manipulation of the argument selector leads to sql injection. The attack can be initiated remotely. • https://github.com/dovankha/CVE-2024-34220 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3421 – SourceCodester Online Courseware deactivatestud.php sql injection
https://notcve.org/view.php?id=CVE-2024-3421
07 Apr 2024 — A vulnerability was found in SourceCodester Online Courseware 1.0. It has been classified as critical. This affects an unknown part of the file admin/deactivatestud.php. The manipulation of the argument selector leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-06.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3420 – SourceCodester Online Courseware saveedit.php sql injection
https://notcve.org/view.php?id=CVE-2024-3420
07 Apr 2024 — A vulnerability was found in SourceCodester Online Courseware 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/saveedit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-05.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •