Alumni Management System Project ≫ Alumni Management System
6 vulnerabilities found.
CVE-2021-25210
- EPSS 0.94%
- Published 22.07.2021 19:15:08
- Last modified 21.11.2024 05:54:32
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
CVE-2021-25212
- EPSS 0.51%
- Published 22.07.2021 19:15:08
- Last modified 21.11.2024 05:54:33
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.
CVE-2020-29214
- EPSS 47.27%
- Published 15.06.2021 20:15:11
- Last modified 21.11.2024 05:23:47
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
CVE-2020-28070
- EPSS 9.39%
- Published 23.12.2020 18:15:12
- Last modified 21.11.2024 05:22:18
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
CVE-2020-28071
- EPSS 0.29%
- Published 23.12.2020 18:15:12
- Last modified 21.11.2024 05:22:18
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' ...
CVE-2020-28072
- EPSS 2.64%
- Published 15.12.2020 21:15:15
- Last modified 21.11.2024 05:22:18
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.