5.3
CVE-2024-8563 - SourceCodester PHP CRUD update.php cross site scripting
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. It is possible to initiate the attack remoβ¦
5.3
CVE-2024-8562 - SourceCodester PHP CRUD Add.php cross site scripting
A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. The attack may be launched remβ¦
5.3
CVE-2024-8561 - SourceCodester PHP CRUD Delete Person delete.php sql injection
A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation of the argument person leads to sql injection. The attack caβ¦
5.3
CVE-2024-8560 - SourceCodester Simple Invoice Generator System save_invoice.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tenderedβ¦
5.1
CVE-2024-8559 - SourceCodester Online Food Menu delete-menu.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql injection. The attack may be initiated remotely. The exploitβ¦
9.9
CVE-2024-38650 -
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.
6.5
CVE-2024-42021 -
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
8.8
CVE-2024-40718 -
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
8.8
CVE-2024-42023 -
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.
8.3
CVE-2024-40714 -
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.