CVE-2023-36375
- EPSS 0.87%
- Veröffentlicht 10.07.2023 17:15:09
- Zuletzt bearbeitet 11.11.2025 18:15:33
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the...
CVE-2023-36376
- EPSS 0.59%
- Veröffentlicht 10.07.2023 16:15:53
- Zuletzt bearbeitet 21.11.2024 08:09:37
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.
CVE-2023-34647
- EPSS 0.36%
- Veröffentlicht 28.06.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:29
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34652
- EPSS 0.49%
- Veröffentlicht 28.06.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:29
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
CVE-2021-43137
- EPSS 0.51%
- Veröffentlicht 01.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:43
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
CVE-2020-25270
- EPSS 3.19%
- Veröffentlicht 08.10.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:17:49
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
- EPSS 2.11%
- Veröffentlicht 08.01.2020 18:15:13
- Zuletzt bearbeitet 11.11.2025 19:15:34
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.