lopalopa CVE Vulnerabilities & Metrics

Focus on lopalopa vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About lopalopa Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with lopalopa. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total lopalopa CVEs: 77
Earliest CVE date: 08 Jan 2024, 09:15 UTC
Latest CVE date: 09 Dec 2024, 18:15 UTC

Latest CVE reference: CVE-2024-54935

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 75

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 3650.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 3650.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical lopalopa CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.64

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 54
4.0-6.9 21
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS lopalopa CVEs

These are the five CVEs with the highest CVSS scores for lopalopa, sorted by severity first and recency.

All CVEs for lopalopa

CVE-2024-54935 lopalopa vulnerability CVSS: 0 09 Dec 2024, 18:15 UTC

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.

CVE-2024-54933 lopalopa vulnerability CVSS: 0 09 Dec 2024, 18:15 UTC

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

CVE-2024-54930 lopalopa vulnerability CVSS: 0 09 Dec 2024, 18:15 UTC

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

CVE-2024-54922 lopalopa vulnerability CVSS: 0 09 Dec 2024, 18:15 UTC

A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.

CVE-2024-54926 lopalopa vulnerability CVSS: 0 09 Dec 2024, 17:15 UTC

A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.

CVE-2024-54920 lopalopa vulnerability CVSS: 0 09 Dec 2024, 15:15 UTC

A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.

CVE-2024-54919 lopalopa vulnerability CVSS: 0 09 Dec 2024, 15:15 UTC

A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter.

CVE-2024-54937 lopalopa vulnerability CVSS: 0 09 Dec 2024, 14:15 UTC

A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.

CVE-2024-54936 lopalopa vulnerability CVSS: 0 09 Dec 2024, 14:15 UTC

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.

CVE-2024-54929 lopalopa vulnerability CVSS: 0 09 Dec 2024, 14:15 UTC

KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

CVE-2024-50831 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

CVE-2024-50830 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.

CVE-2024-50829 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.

CVE-2024-50828 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.

CVE-2024-50827 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

CVE-2024-50826 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.

CVE-2024-50825 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.

CVE-2024-50824 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

CVE-2024-50823 lopalopa vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

CVE-2024-50836 lopalopa vulnerability CVSS: 0 14 Nov 2024, 17:15 UTC

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and lastname parameters.

CVE-2024-50835 lopalopa vulnerability CVSS: 0 14 Nov 2024, 17:15 UTC

A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.

CVE-2024-50834 lopalopa vulnerability CVSS: 0 14 Nov 2024, 17:15 UTC

A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.

CVE-2024-50833 lopalopa vulnerability CVSS: 0 14 Nov 2024, 17:15 UTC

A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.

CVE-2024-50832 lopalopa vulnerability CVSS: 0 14 Nov 2024, 17:15 UTC

A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

CVE-2024-42793 lopalopa vulnerability CVSS: 0 28 Aug 2024, 20:15 UTC

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

CVE-2024-41236 lopalopa vulnerability CVSS: 0 28 Aug 2024, 18:15 UTC

A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page

CVE-2024-42792 lopalopa vulnerability CVSS: 0 26 Aug 2024, 17:15 UTC

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.

CVE-2024-42790 lopalopa vulnerability CVSS: 0 26 Aug 2024, 17:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter.

CVE-2024-42786 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.

CVE-2024-42785 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

CVE-2024-42784 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

CVE-2024-42783 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.

CVE-2024-42782 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.

CVE-2024-42781 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.

CVE-2024-42780 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2024-42779 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2024-42778 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2024-42777 lopalopa vulnerability CVSS: 0 21 Aug 2024, 18:15 UTC

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2024-41238 lopalopa vulnerability CVSS: 0 08 Aug 2024, 16:15 UTC

A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

CVE-2024-41239 lopalopa vulnerability CVSS: 0 07 Aug 2024, 19:15 UTC

A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field.

CVE-2024-41237 lopalopa vulnerability CVSS: 0 07 Aug 2024, 19:15 UTC

A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

CVE-2024-41242 lopalopa vulnerability CVSS: 0 07 Aug 2024, 18:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.

CVE-2024-41241 lopalopa vulnerability CVSS: 0 07 Aug 2024, 18:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.

CVE-2024-41240 lopalopa vulnerability CVSS: 0 07 Aug 2024, 18:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter.

CVE-2024-41250 lopalopa vulnerability CVSS: 0 07 Aug 2024, 17:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.

CVE-2024-41245 lopalopa vulnerability CVSS: 0 07 Aug 2024, 17:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.

CVE-2024-41244 lopalopa vulnerability CVSS: 0 07 Aug 2024, 17:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.

CVE-2024-41243 lopalopa vulnerability CVSS: 0 07 Aug 2024, 17:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.

CVE-2024-41252 lopalopa vulnerability CVSS: 0 07 Aug 2024, 16:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration.

CVE-2024-41251 lopalopa vulnerability CVSS: 0 07 Aug 2024, 16:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration.

CVE-2024-41249 lopalopa vulnerability CVSS: 0 07 Aug 2024, 16:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.

CVE-2024-41248 lopalopa vulnerability CVSS: 0 07 Aug 2024, 16:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.

CVE-2024-41247 lopalopa vulnerability CVSS: 0 07 Aug 2024, 16:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry.

CVE-2024-41246 lopalopa vulnerability CVSS: 0 07 Aug 2024, 16:15 UTC

An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.

CVE-2024-5376 lopalopa vulnerability CVSS: 4.0 26 May 2024, 21:15 UTC

A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file view_each_faculty.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266288.

CVE-2024-5375 lopalopa vulnerability CVSS: 4.0 26 May 2024, 20:15 UTC

A vulnerability has been found in Kashipara College Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file submit_student.php. The manipulation of the argument address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266287.

CVE-2024-5374 lopalopa vulnerability CVSS: 4.0 26 May 2024, 20:15 UTC

A vulnerability, which was classified as problematic, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file submit_new_faculty.php. The manipulation of the argument address leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-266286 is the identifier assigned to this vulnerability.

CVE-2024-5373 lopalopa vulnerability CVSS: 4.0 26 May 2024, 19:15 UTC

A vulnerability, which was classified as problematic, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file submit_login.php. The manipulation of the argument usertype leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266285 was assigned to this vulnerability.

CVE-2024-5372 lopalopa vulnerability CVSS: 4.0 26 May 2024, 19:15 UTC

A vulnerability classified as problematic was found in Kashipara College Management System 1.0. This vulnerability affects unknown code of the file submit_extracurricular_activity.php. The manipulation of the argument activity_contact leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266284.

CVE-2024-5371 lopalopa vulnerability CVSS: 4.0 26 May 2024, 18:15 UTC

A vulnerability classified as problematic has been found in Kashipara College Management System 1.0. This affects an unknown part of the file submit_enroll_student.php. The manipulation of the argument class_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266283.

CVE-2024-5370 lopalopa vulnerability CVSS: 4.0 26 May 2024, 18:15 UTC

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file submit_enroll_staff.php. The manipulation of the argument class_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266282 is the identifier assigned to this vulnerability.

CVE-2024-5369 lopalopa vulnerability CVSS: 4.0 26 May 2024, 17:15 UTC

A vulnerability was found in Kashipara College Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file submit_admin.php. The manipulation of the argument admin_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266281 was assigned to this vulnerability.

CVE-2024-5368 lopalopa vulnerability CVSS: 4.0 26 May 2024, 16:15 UTC

A vulnerability was found in Kashipara College Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266280.

CVE-2024-5367 lopalopa vulnerability CVSS: 4.0 26 May 2024, 15:15 UTC

A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file each_extracurricula_activities.php. The manipulation of the argument id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266279.

CVE-2024-4905 lopalopa vulnerability CVSS: 6.5 15 May 2024, 18:15 UTC

A vulnerability classified as critical has been found in Kashipara College Management System 1.0. Affected is an unknown function of the file view_students_each_detail.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264438 is the identifier assigned to this vulnerability.

CVE-2024-4808 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.

CVE-2024-4807 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability, which was classified as critical, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file delete_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263927.

CVE-2024-4806 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability classified as critical was found in Kashipara College Management System 1.0. This vulnerability affects unknown code of the file each_extracurricula_activities.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263926 is the identifier assigned to this vulnerability.

CVE-2024-4805 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability classified as critical has been found in Kashipara College Management System 1.0. This affects an unknown part of the file edit_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263925 was assigned to this vulnerability.

CVE-2024-4804 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.

CVE-2024-4803 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability was found in Kashipara College Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file submit_admin.php. The manipulation of the argument phone leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263923.

CVE-2024-4802 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability was found in Kashipara College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file submit_extracurricular_activity.php. The manipulation of the argument activity_datetime leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263922 is the identifier assigned to this vulnerability.

CVE-2024-4801 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability was found in Kashipara College Management System 1.0 and classified as critical. This issue affects some unknown processing of the file submit_new_faculty.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263921 was assigned to this vulnerability.

CVE-2024-4800 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability has been found in Kashipara College Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file submit_student.php. The manipulation of the argument date_of_birth leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263920.

CVE-2024-4799 lopalopa vulnerability CVSS: 6.5 14 May 2024, 15:44 UTC

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263919.

CVE-2024-0307 lopalopa vulnerability CVSS: 7.5 08 Jan 2024, 10:15 UTC

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249874 is the identifier assigned to this vulnerability.

CVE-2024-0306 lopalopa vulnerability CVSS: 7.5 08 Jan 2024, 09:15 UTC

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249873 was assigned to this vulnerability.