CVE-2025-3141
- EPSS 0.24%
- Veröffentlicht 03.04.2025 05:15:42
- Zuletzt bearbeitet 09.04.2025 20:08:13
A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_category.php. The manipulation of the argument ID leads to sql injection. T...
CVE-2025-3140
- EPSS 0.2%
- Veröffentlicht 03.04.2025 05:15:40
- Zuletzt bearbeitet 09.04.2025 20:15:21
A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /view_category.php. The manipulation of the argument ID leads to sql injection. It is possib...
CVE-2024-46293
- EPSS 0.31%
- Veröffentlicht 30.09.2024 15:15:06
- Zuletzt bearbeitet 28.04.2025 18:07:39
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session t...
CVE-2024-32167
- EPSS 0.15%
- Veröffentlicht 10.06.2024 20:15:13
- Zuletzt bearbeitet 21.11.2024 09:14:34
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.
CVE-2024-25217
- EPSS 0.15%
- Veröffentlicht 14.02.2024 15:15:09
- Zuletzt bearbeitet 27.03.2025 20:15:23
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.
CVE-2022-3716
- EPSS 0.21%
- Veröffentlicht 27.10.2022 10:15:11
- Zuletzt bearbeitet 21.11.2024 07:20:06
A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the argument First Name...
CVE-2022-3714
- EPSS 0.23%
- Veröffentlicht 27.10.2022 10:15:10
- Zuletzt bearbeitet 21.11.2024 07:20:05
A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is ...