CVE-2023-24204
- EPSS 0.35%
- Veröffentlicht 14.05.2024 17:15:15
- Zuletzt bearbeitet 23.04.2025 16:33:43
SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.
CVE-2023-24203
- EPSS 0.3%
- Veröffentlicht 14.05.2024 17:15:13
- Zuletzt bearbeitet 23.04.2025 16:33:37
Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).
CVE-2023-24655
- EPSS 0.25%
- Veröffentlicht 23.03.2023 01:15:12
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
CVE-2023-24728
- EPSS 0.43%
- Veröffentlicht 15.03.2023 14:15:11
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
CVE-2023-24729
- EPSS 1.46%
- Veröffentlicht 15.03.2023 14:15:11
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
CVE-2023-24730
- EPSS 1.46%
- Veröffentlicht 15.03.2023 14:15:11
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.
CVE-2023-24731
- EPSS 0.43%
- Veröffentlicht 15.03.2023 14:15:11
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.
CVE-2023-24732
- EPSS 0.43%
- Veröffentlicht 15.03.2023 14:15:11
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.
CVE-2023-24364
- EPSS 0.26%
- Veröffentlicht 27.02.2023 16:15:13
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.
CVE-2023-24651
- EPSS 0.33%
- Veröffentlicht 27.02.2023 16:15:13
- Zuletzt bearbeitet 27.06.2025 19:05:16
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.