CVE-2024-25351
- EPSS 0.08%
- Veröffentlicht 28.02.2024 22:15:26
- Zuletzt bearbeitet 27.03.2025 15:09:22
SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL commands via the editid parameter.
CVE-2024-25350
- EPSS 0.11%
- Veröffentlicht 28.02.2024 22:15:26
- Zuletzt bearbeitet 27.03.2025 15:09:10
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.
CVE-2023-41614
- EPSS 0.06%
- Veröffentlicht 21.09.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:21:21
A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.
CVE-2023-41615
- EPSS 0.13%
- Veröffentlicht 08.09.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:21:21
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
CVE-2022-40925
- EPSS 0.43%
- Veröffentlicht 26.09.2022 13:15:11
- Zuletzt bearbeitet 21.05.2025 18:15:51
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.
CVE-2022-40924
- EPSS 0.43%
- Veröffentlicht 26.09.2022 13:15:11
- Zuletzt bearbeitet 06.02.2026 18:15:54
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
CVE-2022-40932
- EPSS 0.43%
- Veröffentlicht 22.09.2022 16:15:09
- Zuletzt bearbeitet 27.05.2025 16:15:28
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.
CVE-2022-2804
- EPSS 0.42%
- Veröffentlicht 12.08.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:43
A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is...
CVE-2022-2803
- EPSS 0.23%
- Veröffentlicht 12.08.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:43
A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to sql injection. The attack may ...
CVE-2022-33075
- EPSS 0.19%
- Veröffentlicht 05.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:07:30
A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.