6.3

CVSS3.1

CVE-2024-34092 -

An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed release.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

7.3

CVSS3.1

CVE-2024-34091 -

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When vic…

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 18, 2025, 2:54 p.m.

7.3

CVSS3.1

CVE-2024-34090 -

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control Panel (ACP) did not previously escape content appropriately. 6.14 P3 (6.14.0.3) is also a fixed release.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 18, 2025, 5:30 p.m.

9.8

CVSS3.1

CVE-2024-33411 -

A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the my_index parameter.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:20 p.m.

9.8

CVSS3.1

CVE-2024-33409 -

SQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the name parameter.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:20 p.m.

5.9

CVSS3.1

CVE-2024-33407 -

SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:20 p.m.

7.3

CVSS3.1

CVE-2024-33406 -

SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:20 p.m.

8.3

CVSS3.1

CVE-2024-33404 -

A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:20 p.m.

9.8

CVSS3.1

CVE-2024-33403 -

A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:20 p.m.

6.3

CVSS3.1

CVE-2024-33121 -

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.

πŸ“… Published: May 6, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 4:04 p.m.
Total resulsts: 349182
Page 9978 of 34,919
Β« previous page Β» next page
Filters