angeljudesuarez CVE Vulnerabilities & Metrics

Focus on angeljudesuarez vulnerabilities and metrics.

Last updated: 25 Nov 2025, 23:25 UTC

About angeljudesuarez Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with angeljudesuarez. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total angeljudesuarez CVEs: 141
Earliest CVE date: 05 Apr 2022, 20:15 UTC
Latest CVE date: 19 Nov 2025, 23:15 UTC

Latest CVE reference: CVE-2025-13421

Rolling Stats

30-day Count (Rolling): 12
365-day Count (Rolling): 76

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 71.43%
Year Variation (Calendar): 28.81%

Month Growth Rate (30-day Rolling): 71.43%
Year Growth Rate (365-day Rolling): 28.81%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical angeljudesuarez CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.08

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 16
4.0-6.9 75
7.0-8.9 50
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS angeljudesuarez CVEs

These are the five CVEs with the highest CVSS scores for angeljudesuarez, sorted by severity first and recency.

All CVEs for angeljudesuarez

CVE-2025-13421 angeljudesuarez vulnerability CVSS: 7.5 19 Nov 2025, 23:15 UTC

A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of the argument noticeDesc leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-13420 angeljudesuarez vulnerability CVSS: 7.5 19 Nov 2025, 23:15 UTC

A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argument eventSubject causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-13287 angeljudesuarez vulnerability CVSS: 6.5 17 Nov 2025, 15:15 UTC

A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /index.php?page=categories. Executing manipulation of the argument id/category can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-13286 angeljudesuarez vulnerability CVSS: 6.5 17 Nov 2025, 14:15 UTC

A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

CVE-2025-13285 angeljudesuarez vulnerability CVSS: 7.5 17 Nov 2025, 14:15 UTC

A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

CVE-2025-13061 angeljudesuarez vulnerability CVSS: 6.5 12 Nov 2025, 21:15 UTC

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVE-2025-12617 angeljudesuarez vulnerability CVSS: 7.5 03 Nov 2025, 05:15 UTC

A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing manipulation of the argument Password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

CVE-2025-12608 angeljudesuarez vulnerability CVSS: 7.5 03 Nov 2025, 01:15 UTC

A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

CVE-2025-12607 angeljudesuarez vulnerability CVSS: 7.5 03 Nov 2025, 01:15 UTC

A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVE-2025-12606 angeljudesuarez vulnerability CVSS: 7.5 03 Nov 2025, 00:15 UTC

A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVE-2025-12605 angeljudesuarez vulnerability CVSS: 7.5 02 Nov 2025, 23:15 UTC

A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

CVE-2025-12604 angeljudesuarez vulnerability CVSS: 7.5 02 Nov 2025, 22:15 UTC

A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11736 angeljudesuarez vulnerability CVSS: 7.5 14 Oct 2025, 18:15 UTC

A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

CVE-2025-11119 angeljudesuarez vulnerability CVSS: 5.0 28 Sep 2025, 21:15 UTC

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

CVE-2025-11101 angeljudesuarez vulnerability CVSS: 7.5 28 Sep 2025, 07:15 UTC

A security flaw has been discovered in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/company/index.php?view=edit. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

CVE-2025-11090 angeljudesuarez vulnerability CVSS: 6.5 28 Sep 2025, 01:15 UTC

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected is an unknown function of the file /admin/employee/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

CVE-2025-11088 angeljudesuarez vulnerability CVSS: 6.5 28 Sep 2025, 00:15 UTC

A weakness has been identified in itsourcecode Open Source Job Portal 1.0. Impacted is an unknown function of the file /admin/vacancy/index.php?view=edit. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

CVE-2025-11078 angeljudesuarez vulnerability CVSS: 6.5 27 Sep 2025, 21:15 UTC

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation of the argument photo leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

CVE-2025-11054 angeljudesuarez vulnerability CVSS: 6.5 27 Sep 2025, 10:15 UTC

A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/category/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-11041 angeljudesuarez vulnerability CVSS: 6.5 26 Sep 2025, 20:15 UTC

A vulnerability has been found in itsourcecode Open Source Job Portal 1.0. Affected by this issue is some unknown functionality of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11040 angeljudesuarez vulnerability CVSS: 7.5 26 Sep 2025, 20:15 UTC

A vulnerability was detected in code-projects Hostel Management System 1.0. Affected by this issue is some unknown functionality of the file /justines/admin/mod_users/index.php?view=view. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

CVE-2025-11038 angeljudesuarez vulnerability CVSS: 6.5 26 Sep 2025, 20:15 UTC

A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of the file /details.php?action=post. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-10834 angeljudesuarez vulnerability CVSS: 7.5 23 Sep 2025, 03:15 UTC

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. This affects an unknown function of the file /jobportal/admin/login.php. Such manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVE-2025-10813 angeljudesuarez vulnerability CVSS: 7.5 22 Sep 2025, 20:15 UTC

A vulnerability was found in code-projects Hostel Management System 1.0. Affected is an unknown function of the file /justines/admin/mod_reports/index.php. The manipulation of the argument Home results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

CVE-2025-10812 angeljudesuarez vulnerability CVSS: 7.5 22 Sep 2025, 20:15 UTC

A vulnerability has been found in code-projects Hostel Management System 1.0. This impacts an unknown function of the file /justines/admin/mod_amenities/index.php?view=view. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-10811 angeljudesuarez vulnerability CVSS: 7.5 22 Sep 2025, 19:15 UTC

A flaw has been found in code-projects Hostel Management System 1.0. This affects an unknown function of the file /justines/admin/mod_comments/index.php?view=view. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

CVE-2025-10799 angeljudesuarez vulnerability CVSS: 7.5 22 Sep 2025, 13:16 UTC

A security flaw has been discovered in code-projects Hostel Management System 1.0. The affected element is an unknown function of the file /justines/admin/mod_reservation/index.php?view=view. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

CVE-2025-10798 angeljudesuarez vulnerability CVSS: 7.5 22 Sep 2025, 13:16 UTC

A vulnerability was identified in code-projects Hostel Management System 1.0. Impacted is an unknown function of the file /justines/admin/mod_roomtype/index.php?view=view. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

CVE-2025-10797 angeljudesuarez vulnerability CVSS: 7.5 22 Sep 2025, 13:16 UTC

A vulnerability was determined in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /justines/index.php. This manipulation of the argument log_email causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2025-10796 angeljudesuarez vulnerability CVSS: 7.5 22 Sep 2025, 12:15 UTC

A vulnerability was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /justines/admin/login.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVE-2025-10620 angeljudesuarez vulnerability CVSS: 6.5 17 Sep 2025, 22:15 UTC

A flaw has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file /editp2.php. Executing manipulation of the argument id/firstname/lastname/type/age/address can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

CVE-2025-10618 angeljudesuarez vulnerability CVSS: 6.5 17 Sep 2025, 21:15 UTC

A security vulnerability has been detected in itsourcecode Online Clinic Management System 1.0. Affected by this issue is some unknown functionality of the file transact.php. Such manipulation of the argument firstname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Other parameters might be affected as well.

CVE-2025-10616 angeljudesuarez vulnerability CVSS: 6.5 17 Sep 2025, 21:15 UTC

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

CVE-2025-10615 angeljudesuarez vulnerability CVSS: 6.5 17 Sep 2025, 20:15 UTC

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be used.

CVE-2025-9840 angeljudesuarez vulnerability CVSS: 6.5 02 Sep 2025, 23:15 UTC

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-9768 angeljudesuarez vulnerability CVSS: 6.5 01 Sep 2025, 08:15 UTC

A vulnerability was identified in itsourcecode Sports Management System 1.0. This impacts an unknown function of the file /Admin/mode.php. The manipulation of the argument code leads to sql injection. The attack is possible to be carried out remotely.

CVE-2025-9767 angeljudesuarez vulnerability CVSS: 7.5 01 Sep 2025, 07:15 UTC

A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /Admin/sporttype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2025-9766 angeljudesuarez vulnerability CVSS: 7.5 01 Sep 2025, 07:15 UTC

A vulnerability was found in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

CVE-2025-9765 angeljudesuarez vulnerability CVSS: 7.5 01 Sep 2025, 06:15 UTC

A vulnerability has been found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/tournament_details.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-9764 angeljudesuarez vulnerability CVSS: 7.5 01 Sep 2025, 06:15 UTC

A flaw has been found in itsourcecode Sports Management System 1.0. Impacted is an unknown function of the file /Admin/resultdetails.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVE-2025-9596 angeljudesuarez vulnerability CVSS: 7.5 29 Aug 2025, 00:15 UTC

A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /login.php. This manipulation of the argument User causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2025-9156 angeljudesuarez vulnerability CVSS: 7.5 19 Aug 2025, 20:15 UTC

A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

CVE-2025-8925 angeljudesuarez vulnerability CVSS: 7.5 13 Aug 2025, 19:15 UTC

A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file /Admin/match.php. The manipulation of the argument code leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8135 angeljudesuarez vulnerability CVSS: 6.5 25 Jul 2025, 07:15 UTC

A vulnerability, which was classified as critical, has been found in itsourcecode Insurance Management System 1.0. This issue affects some unknown processing of the file /updateAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7905 angeljudesuarez vulnerability CVSS: 6.5 20 Jul 2025, 19:15 UTC

A vulnerability has been found in itsourcecode Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /insertPayment.php. The manipulation of the argument recipt_no leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7904 angeljudesuarez vulnerability CVSS: 6.5 20 Jul 2025, 17:15 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Insurance Management System 1.0. This affects an unknown part of the file /insertNominee.php. The manipulation of the argument nominee_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7212 angeljudesuarez vulnerability CVSS: 6.5 09 Jul 2025, 03:15 UTC

A vulnerability was found in itsourcecode Insurance Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insertAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4726 angeljudesuarez vulnerability CVSS: 7.5 15 May 2025, 23:15 UTC

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view_student.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4725 angeljudesuarez vulnerability CVSS: 7.5 15 May 2025, 22:15 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. This affects an unknown part of the file /view_drive.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4724 angeljudesuarez vulnerability CVSS: 7.5 15 May 2025, 22:15 UTC

A vulnerability, which was classified as critical, has been found in itsourcecode Placement Management System 1.0. Affected by this issue is some unknown functionality of the file /student_profile.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4723 angeljudesuarez vulnerability CVSS: 7.5 15 May 2025, 22:15 UTC

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /all_student.php. The manipulation of the argument delete leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4722 angeljudesuarez vulnerability CVSS: 7.5 15 May 2025, 22:15 UTC

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /edit_profile.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4721 angeljudesuarez vulnerability CVSS: 7.5 15 May 2025, 21:15 UTC

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /drive.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4025 angeljudesuarez vulnerability CVSS: 7.5 28 Apr 2025, 15:15 UTC

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2025-4024 angeljudesuarez vulnerability CVSS: 7.5 28 Apr 2025, 15:15 UTC

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2025-4023 angeljudesuarez vulnerability CVSS: 7.5 28 Apr 2025, 14:15 UTC

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_company.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2025-25878 angeljudesuarez vulnerability CVSS: 0 21 Feb 2025, 18:16 UTC

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL injection to obtain sensitive data.

CVE-2025-25877 angeljudesuarez vulnerability CVSS: 0 21 Feb 2025, 18:16 UTC

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /admin.php. The attack can use SQL injection to obtain sensitive data.

CVE-2025-25876 angeljudesuarez vulnerability CVSS: 0 21 Feb 2025, 18:16 UTC

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The attack can use SQL injection to obtain sensitive data.

CVE-2025-25875 angeljudesuarez vulnerability CVSS: 0 21 Feb 2025, 18:16 UTC

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data.

CVE-2024-50656 angeljudesuarez vulnerability CVSS: 0 03 Feb 2025, 19:15 UTC

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

CVE-2025-0950 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 20:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file staffview.php. The manipulation of the argument staffid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0949 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 19:15 UTC

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file partview.php. The manipulation of the argument typeid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0948 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 18:15 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file incview.php. The manipulation of the argument incid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0947 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 17:15 UTC

A vulnerability, which was classified as critical, has been found in itsourcecode Tailoring Management System 1.0. Affected by this issue is some unknown functionality of the file expview.php. The manipulation of the argument expid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0946 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 16:15 UTC

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file templatedelete.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0945 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 15:15 UTC

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file typedelete.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0944 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 13:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file customerview.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0943 angeljudesuarez vulnerability CVSS: 6.5 01 Feb 2025, 11:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file deldoc.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0873 angeljudesuarez vulnerability CVSS: 6.5 30 Jan 2025, 17:15 UTC

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. The manipulation of the argument id/address/fullname/phonenumber/email/city/comment leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0872 angeljudesuarez vulnerability CVSS: 6.5 30 Jan 2025, 16:15 UTC

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /addpayment.php. The manipulation of the argument id/amount/desc/inccat leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0582 angeljudesuarez vulnerability CVSS: 5.8 20 Jan 2025, 03:15 UTC

A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the file /add-pig.php. The manipulation of the argument pigphoto leads to unrestricted upload. The attack can be initiated remotely.

CVE-2025-0561 angeljudesuarez vulnerability CVSS: 6.5 19 Jan 2025, 00:15 UTC

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-pig.php. The manipulation of the argument pigno leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0540 angeljudesuarez vulnerability CVSS: 6.5 17 Jan 2025, 21:15 UTC

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The manipulation of the argument expcat leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12785 angeljudesuarez vulnerability CVSS: 6.5 19 Dec 2024, 15:15 UTC

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file sendmail.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12783 angeljudesuarez vulnerability CVSS: 4.0 19 Dec 2024, 13:15 UTC

A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /billaction.php. The manipulation of the argument extra-cost leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11631 angeljudesuarez vulnerability CVSS: 6.5 23 Nov 2024, 12:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /expedit.php. The manipulation of the argument expcat leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-50972 angeljudesuarez vulnerability CVSS: 0 13 Nov 2024, 16:15 UTC

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

CVE-2024-50971 angeljudesuarez vulnerability CVSS: 0 13 Nov 2024, 16:15 UTC

A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.

CVE-2024-11074 angeljudesuarez vulnerability CVSS: 6.5 11 Nov 2024, 18:15 UTC

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file /incadd.php. The manipulation of the argument inccat/desc/date/amount leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "inccat" to be affected. But it must be assumed "desc", "date", and "amount" are affected as well.

CVE-2024-10759 angeljudesuarez vulnerability CVSS: 6.5 04 Nov 2024, 04:15 UTC

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The manipulation of the argument pigno/weight/arrived/breed/remark/status leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "pigno" to be affected. But it must be assumed that other parameters are affected as well.

CVE-2024-10738 angeljudesuarez vulnerability CVSS: 6.5 03 Nov 2024, 17:15 UTC

A vulnerability classified as critical was found in itsourcecode Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file manage-breed.php. The manipulation of the argument breed leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10609 angeljudesuarez vulnerability CVSS: 6.5 01 Nov 2024, 01:15 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. The manipulation of the argument sex leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-48656 angeljudesuarez vulnerability CVSS: 0 22 Oct 2024, 22:15 UTC

Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.

CVE-2024-48597 angeljudesuarez vulnerability CVSS: 0 21 Oct 2024, 20:15 UTC

Online Clinic Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /success/editp.php?action=edit.

CVE-2024-46300 angeljudesuarez vulnerability CVSS: 0 07 Oct 2024, 17:15 UTC

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

CVE-2024-9036 angeljudesuarez vulnerability CVSS: 6.5 20 Sep 2024, 16:15 UTC

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-8611 angeljudesuarez vulnerability CVSS: 6.5 09 Sep 2024, 21:15 UTC

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-8570 angeljudesuarez vulnerability CVSS: 6.5 08 Sep 2024, 07:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-44728 angeljudesuarez vulnerability CVSS: 0 05 Sep 2024, 17:15 UTC

Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.

CVE-2024-44727 angeljudesuarez vulnerability CVSS: 0 05 Sep 2024, 17:15 UTC

Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.

CVE-2024-8220 angeljudesuarez vulnerability CVSS: 6.5 27 Aug 2024, 22:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file staffedit.php. The manipulation of the argument id/stafftype/address/fullname/phonenumber/salary leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-8171 angeljudesuarez vulnerability CVSS: 6.5 26 Aug 2024, 16:15 UTC

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file staffcatedit.php. The manipulation of the argument title leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-8139 angeljudesuarez vulnerability CVSS: 6.5 25 Aug 2024, 01:15 UTC

A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file search_list.php. The manipulation of the argument user leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7913 angeljudesuarez vulnerability CVSS: 7.5 18 Aug 2024, 22:15 UTC

A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addclient1.php. The manipulation of the argument lname/fname/mi/address/contact/meterReader leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7839 angeljudesuarez vulnerability CVSS: 7.5 15 Aug 2024, 21:15 UTC

A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7680 angeljudesuarez vulnerability CVSS: 6.5 12 Aug 2024, 13:38 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /incedit.php?id=4. The manipulation of the argument id/inccat/desc/date/amount leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7506 angeljudesuarez vulnerability CVSS: 6.5 06 Aug 2024, 05:15 UTC

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The manipulation of the argument bgimg leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273649 was assigned to this vulnerability.

CVE-2024-7500 angeljudesuarez vulnerability CVSS: 6.5 06 Aug 2024, 04:16 UTC

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273626 is the identifier assigned to this vulnerability.

CVE-2024-7499 angeljudesuarez vulnerability CVSS: 6.5 06 Aug 2024, 03:15 UTC

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file flights.php. The manipulation of the argument departure_airport_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273625 was assigned to this vulnerability.

CVE-2024-7498 angeljudesuarez vulnerability CVSS: 7.5 06 Aug 2024, 03:15 UTC

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273624.

CVE-2024-7497 angeljudesuarez vulnerability CVSS: 6.5 06 Aug 2024, 02:15 UTC

A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273623.

CVE-2024-7496 angeljudesuarez vulnerability CVSS: 6.5 06 Aug 2024, 02:15 UTC

A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273622 is the identifier assigned to this vulnerability.

CVE-2024-7455 angeljudesuarez vulnerability CVSS: 6.5 04 Aug 2024, 12:16 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file partedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273549 was assigned to this vulnerability.

CVE-2024-7452 angeljudesuarez vulnerability CVSS: 6.5 04 Aug 2024, 04:17 UTC

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been classified as critical. This affects an unknown part of the file view_company.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273543.

CVE-2024-7451 angeljudesuarez vulnerability CVSS: 6.5 04 Aug 2024, 04:17 UTC

A vulnerability was found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file apply_now.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273542 is the identifier assigned to this vulnerability.

CVE-2024-7450 angeljudesuarez vulnerability CVSS: 6.0 04 Aug 2024, 03:15 UTC

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resume_upload.php of the component Image Handler. The manipulation of the argument fileToUpload leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273541 was assigned to this vulnerability.

CVE-2024-7449 angeljudesuarez vulnerability CVSS: 7.5 04 Aug 2024, 03:15 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273540.

CVE-2024-7195 angeljudesuarez vulnerability CVSS: 6.5 29 Jul 2024, 11:15 UTC

A vulnerability was found in itsourcecode Society Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/check_admin.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272616.

CVE-2024-7194 angeljudesuarez vulnerability CVSS: 6.5 29 Jul 2024, 10:15 UTC

A vulnerability was found in itsourcecode Society Management System 1.0 and classified as critical. This issue affects some unknown processing of the file check_student.php. The manipulation of the argument student_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272615.

CVE-2024-7192 angeljudesuarez vulnerability CVSS: 6.5 29 Jul 2024, 09:15 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/student.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272613 was assigned to this vulnerability.

CVE-2024-7191 angeljudesuarez vulnerability CVSS: 6.5 29 Jul 2024, 09:15 UTC

A vulnerability, which was classified as critical, has been found in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/get_balance.php. The manipulation of the argument student_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272612.

CVE-2024-7190 angeljudesuarez vulnerability CVSS: 6.5 29 Jul 2024, 08:15 UTC

A vulnerability classified as critical was found in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/get_price.php. The manipulation of the argument expenses_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272611.

CVE-2024-40502 angeljudesuarez vulnerability CVSS: 0 22 Jul 2024, 21:15 UTC

SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx

CVE-2024-6958 angeljudesuarez vulnerability CVSS: 6.5 21 Jul 2024, 15:15 UTC

A vulnerability classified as critical was found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /st_update.php of the component Avatar File Handler. The manipulation of the argument personal_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272080.

CVE-2024-6957 angeljudesuarez vulnerability CVSS: 7.5 21 Jul 2024, 15:15 UTC

A vulnerability classified as critical has been found in itsourcecode University Management System 1.0. This affects an unknown part of the file functions.php of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272079.

CVE-2024-6956 angeljudesuarez vulnerability CVSS: 6.5 21 Jul 2024, 14:15 UTC

A vulnerability was found in itsourcecode University Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view_cgpa.php. The manipulation of the argument VR/VN leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272078 is the identifier assigned to this vulnerability.

CVE-2024-6953 angeljudesuarez vulnerability CVSS: 6.5 21 Jul 2024, 12:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sms.php. The manipulation of the argument customer leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272075.

CVE-2024-6952 angeljudesuarez vulnerability CVSS: 6.5 21 Jul 2024, 12:15 UTC

A vulnerability has been found in itsourcecode University Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view_single_result.php?vr=123321&vn=mirage. The manipulation of the argument seme leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-272074 is the identifier assigned to this vulnerability.

CVE-2024-40393 angeljudesuarez vulnerability CVSS: 0 16 Jul 2024, 19:15 UTC

Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.

CVE-2024-6735 angeljudesuarez vulnerability CVSS: 6.5 15 Jul 2024, 00:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file setgeneral.php. The manipulation of the argument sitename/email/mobile/sms/currency leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271456.

CVE-2024-6734 angeljudesuarez vulnerability CVSS: 6.5 15 Jul 2024, 00:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file templateadd.php. The manipulation of the argument title/msg leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271455.

CVE-2024-6733 angeljudesuarez vulnerability CVSS: 6.5 14 Jul 2024, 23:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file templateedit.php. The manipulation of the argument id/title/msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271454 is the identifier assigned to this vulnerability.

CVE-2024-6728 angeljudesuarez vulnerability CVSS: 6.5 14 Jul 2024, 01:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file typeedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271401 was assigned to this vulnerability.

CVE-2024-37872 angeljudesuarez vulnerability CVSS: 0 09 Jul 2024, 20:15 UTC

SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVE-2024-6453 angeljudesuarez vulnerability CVSS: 6.5 02 Jul 2024, 22:15 UTC

A vulnerability was found in itsourcecode Farm Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /quarantine.php?id=3. The manipulation of the argument pigno/breed/reason leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-270241 was assigned to this vulnerability. NOTE: Original submission mentioned parameter pigno only but the VulDB data analysis team determined two additional parameters to be affected as well.

CVE-2024-6372 angeljudesuarez vulnerability CVSS: 6.5 27 Jun 2024, 13:16 UTC

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file customeradd.php. The manipulation of the argument fullname/address/phonenumber/sex/email/city/comment leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269805 was assigned to this vulnerability.

CVE-2024-6192 angeljudesuarez vulnerability CVSS: 7.5 20 Jun 2024, 15:15 UTC

A vulnerability classified as critical was found in itsourcecode Loan Management System 1.0. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269164.

CVE-2024-6191 angeljudesuarez vulnerability CVSS: 7.5 20 Jun 2024, 15:15 UTC

A vulnerability classified as critical has been found in itsourcecode Student Management System 1.0. This affects an unknown part of the file login.php of the component Login Page. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269163.

CVE-2024-6190 angeljudesuarez vulnerability CVSS: 7.5 20 Jun 2024, 15:15 UTC

A vulnerability was found in itsourcecode Farm Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-269162 is the identifier assigned to this vulnerability.

CVE-2024-6109 angeljudesuarez vulnerability CVSS: 6.5 18 Jun 2024, 12:15 UTC

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file addmeasurement.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268855.

CVE-2024-37848 angeljudesuarez vulnerability CVSS: 0 17 Jun 2024, 14:15 UTC

SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.

CVE-2024-6042 angeljudesuarez vulnerability CVSS: 7.5 17 Jun 2024, 00:15 UTC

A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file property-detail.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-268766 is the identifier assigned to this vulnerability.

CVE-2024-5981 angeljudesuarez vulnerability CVSS: 6.5 14 Jun 2024, 02:15 UTC

A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268458 is the identifier assigned to this vulnerability.

CVE-2024-5898 angeljudesuarez vulnerability CVSS: 6.5 12 Jun 2024, 17:15 UTC

A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file print_payroll.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-268142 is the identifier assigned to this vulnerability.

CVE-2022-30002 angeljudesuarez vulnerability CVSS: 6.5 12 May 2022, 16:15 UTC

Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editNominee.php?nominee_id=.

CVE-2022-30001 angeljudesuarez vulnerability CVSS: 7.5 12 May 2022, 16:15 UTC

Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.

CVE-2022-30000 angeljudesuarez vulnerability CVSS: 7.5 12 May 2022, 16:15 UTC

Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.

CVE-2022-29999 angeljudesuarez vulnerability CVSS: 7.5 12 May 2022, 16:15 UTC

Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=.

CVE-2022-29998 angeljudesuarez vulnerability CVSS: 7.5 12 May 2022, 16:15 UTC

Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/clientStatus.php?client_id=.

CVE-2022-27124 angeljudesuarez vulnerability CVSS: 7.5 05 Apr 2022, 20:15 UTC

Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.