projectworlds CVE Vulnerabilities & Metrics

Focus on projectworlds vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About projectworlds Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with projectworlds. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total projectworlds CVEs: 103
Earliest CVE date: 06 Apr 2020, 16:15 UTC
Latest CVE date: 23 Jan 2025, 22:15 UTC

Latest CVE reference: CVE-2024-57328

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 14

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): -75.86%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): -75.86%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical projectworlds CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.69

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 62
4.0-6.9 20
7.0-8.9 20
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS projectworlds CVEs

These are the five CVEs with the highest CVSS scores for projectworlds, sorted by severity first and recency.

All CVEs for projectworlds

CVE-2024-57328 projectworlds vulnerability CVSS: 0 23 Jan 2025, 22:15 UTC

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.

CVE-2024-51327 projectworlds vulnerability CVSS: 0 04 Nov 2024, 18:15 UTC

SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.

CVE-2024-51326 projectworlds vulnerability CVSS: 0 04 Nov 2024, 18:15 UTC

SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.

CVE-2024-10735 projectworlds vulnerability CVSS: 6.5 03 Nov 2024, 14:15 UTC

A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /editNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10734 projectworlds vulnerability CVSS: 6.5 03 Nov 2024, 13:15 UTC

A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /editPayment.php. The manipulation of the argument recipt_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10447 projectworlds vulnerability CVSS: 6.5 28 Oct 2024, 13:15 UTC

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched remotely.

CVE-2024-10446 projectworlds vulnerability CVSS: 6.5 28 Oct 2024, 12:15 UTC

A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10433 projectworlds vulnerability CVSS: 4.0 28 Oct 2024, 00:15 UTC

A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument Name/Comment leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions different parameters to be affected which do not correlate with the screenshots of a successful attack.

CVE-2024-10432 projectworlds vulnerability CVSS: 7.5 28 Oct 2024, 00:15 UTC

A vulnerability has been found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10425 projectworlds vulnerability CVSS: 6.5 27 Oct 2024, 19:15 UTC

A vulnerability was found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /student/project_selection/move_up_project.php of the component Project Selection Page. The manipulation of the argument up leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10424 projectworlds vulnerability CVSS: 6.5 27 Oct 2024, 19:15 UTC

A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/project_selection/remove_project.php of the component Project Selection Page. The manipulation of the argument no leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10423 projectworlds vulnerability CVSS: 6.5 27 Oct 2024, 18:15 UTC

A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file /student/project_selection/project_selection.php of the component Project Selection Page. The manipulation of the argument project_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-42843 projectworlds vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.

CVE-2024-36597 projectworlds vulnerability CVSS: 0 14 Jun 2024, 18:15 UTC

Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

CVE-2024-22922 projectworlds vulnerability CVSS: 0 25 Jan 2024, 22:15 UTC

An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php

CVE-2024-0730 projectworlds vulnerability CVSS: 6.5 19 Jan 2024, 19:15 UTC

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file course_ajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251553 was assigned to this vulnerability.

CVE-2024-0726 projectworlds vulnerability CVSS: 5.0 19 Jan 2024, 18:15 UTC

A vulnerability was found in Project Worlds Student Project Allocation System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin_login.php of the component Admin Login Module. The manipulation of the argument msg with the input test%22%3Cscript%3Ealert(%27Torada%27)%3C/script%3E leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251549 was assigned to this vulnerability.

CVE-2024-0262 projectworlds vulnerability CVSS: 3.3 07 Jan 2024, 02:15 UTC

A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Admin/News.php of the component Create News Page. The manipulation of the argument News with the input </title><scRipt>alert(0x00C57D)</scRipt> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249818 is the identifier assigned to this vulnerability.

CVE-2023-48716 projectworlds vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_id' parameter of the add_classes.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-48689 projectworlds vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-48687 projectworlds vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-48685 projectworlds vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44482 projectworlds vulnerability CVSS: 0 21 Dec 2023, 19:15 UTC

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44481 projectworlds vulnerability CVSS: 0 21 Dec 2023, 19:15 UTC

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45121 projectworlds vulnerability CVSS: 0 21 Dec 2023, 17:15 UTC

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45120 projectworlds vulnerability CVSS: 0 21 Dec 2023, 17:15 UTC

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45119 projectworlds vulnerability CVSS: 0 21 Dec 2023, 16:15 UTC

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the /update.php?q=quiz resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45118 projectworlds vulnerability CVSS: 0 21 Dec 2023, 16:15 UTC

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45117 projectworlds vulnerability CVSS: 0 21 Dec 2023, 16:15 UTC

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the /update.php?q=rmquiz resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45116 projectworlds vulnerability CVSS: 0 21 Dec 2023, 16:15 UTC

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45115 projectworlds vulnerability CVSS: 0 21 Dec 2023, 16:15 UTC

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-48434 projectworlds vulnerability CVSS: 0 20 Dec 2023, 21:15 UTC

Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-48433 projectworlds vulnerability CVSS: 0 20 Dec 2023, 21:15 UTC

Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46800 projectworlds vulnerability CVSS: 0 07 Nov 2023, 22:15 UTC

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the view_profile.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46793 projectworlds vulnerability CVSS: 0 07 Nov 2023, 22:15 UTC

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'day' parameter in the 'register()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46789 projectworlds vulnerability CVSS: 0 07 Nov 2023, 21:15 UTC

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic1' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46788 projectworlds vulnerability CVSS: 0 07 Nov 2023, 21:15 UTC

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter in the 'uploadphoto()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46787 projectworlds vulnerability CVSS: 0 07 Nov 2023, 21:15 UTC

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the auth/auth.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46785 projectworlds vulnerability CVSS: 0 07 Nov 2023, 21:15 UTC

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46679 projectworlds vulnerability CVSS: 0 07 Nov 2023, 21:15 UTC

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' parameter of the index.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-46677 projectworlds vulnerability CVSS: 0 07 Nov 2023, 21:15 UTC

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45347 projectworlds vulnerability CVSS: 0 02 Nov 2023, 15:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45346 projectworlds vulnerability CVSS: 0 02 Nov 2023, 15:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_role' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45345 projectworlds vulnerability CVSS: 0 02 Nov 2023, 15:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_deleted' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45338 projectworlds vulnerability CVSS: 0 02 Nov 2023, 15:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the routers/add-ticket.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45344 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45343 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45342 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45341 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_price' parameter of the routers/menu-router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45340 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/details-router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45336 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the routers/router.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45334 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45325 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45323 projectworlds vulnerability CVSS: 0 02 Nov 2023, 14:15 UTC

Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'name' parameter of the routers/add-item.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-45203 projectworlds vulnerability CVSS: 0 01 Nov 2023, 23:15 UTC

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

CVE-2023-45202 projectworlds vulnerability CVSS: 0 01 Nov 2023, 23:15 UTC

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

CVE-2023-45201 projectworlds vulnerability CVSS: 0 01 Nov 2023, 22:15 UTC

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

CVE-2023-44484 projectworlds vulnerability CVSS: 0 31 Oct 2023, 22:15 UTC

Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstName' parameter of the users/register.php resource is copied into the users/member.php document as plain text between tags. Any input is echoed unmodified in the users/member.php response.

CVE-2023-44480 projectworlds vulnerability CVSS: 0 27 Oct 2023, 21:15 UTC

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44267 projectworlds vulnerability CVSS: 0 26 Oct 2023, 20:15 UTC

Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44174 projectworlds vulnerability CVSS: 0 28 Sep 2023, 22:15 UTC

Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.

CVE-2023-44166 projectworlds vulnerability CVSS: 0 28 Sep 2023, 22:15 UTC

The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44164 projectworlds vulnerability CVSS: 0 28 Sep 2023, 22:15 UTC

The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-44163 projectworlds vulnerability CVSS: 0 28 Sep 2023, 22:15 UTC

The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-43014 projectworlds vulnerability CVSS: 0 28 Sep 2023, 22:15 UTC

Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.

CVE-2023-5185 projectworlds vulnerability CVSS: 0 28 Sep 2023, 21:15 UTC

Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

CVE-2023-5053 projectworlds vulnerability CVSS: 0 28 Sep 2023, 21:15 UTC

Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

CVE-2023-5004 projectworlds vulnerability CVSS: 0 28 Sep 2023, 21:15 UTC

Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

CVE-2023-44173 projectworlds vulnerability CVSS: 0 28 Sep 2023, 21:15 UTC

Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.

CVE-2023-43740 projectworlds vulnerability CVSS: 0 28 Sep 2023, 21:15 UTC

Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

CVE-2023-43013 projectworlds vulnerability CVSS: 0 28 Sep 2023, 21:15 UTC

Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

CVE-2023-43144 projectworlds vulnerability CVSS: 0 22 Sep 2023, 15:15 UTC

Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.

CVE-2022-42066 projectworlds vulnerability CVSS: 0 14 Oct 2022, 15:16 UTC

Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.

CVE-2021-45852 projectworlds vulnerability CVSS: 5.0 16 Mar 2022, 10:15 UTC

An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.

CVE-2021-44866 projectworlds vulnerability CVSS: 5.0 03 Feb 2022, 14:15 UTC

An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

CVE-2021-46024 projectworlds vulnerability CVSS: 7.5 23 Jan 2022, 17:15 UTC

Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.

CVE-2021-46307 projectworlds vulnerability CVSS: 10.0 21 Jan 2022, 16:15 UTC

An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.

CVE-2021-43631 projectworlds vulnerability CVSS: 7.5 22 Dec 2021, 18:15 UTC

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.

CVE-2021-43630 projectworlds vulnerability CVSS: 6.5 22 Dec 2021, 18:15 UTC

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.

CVE-2021-43629 projectworlds vulnerability CVSS: 7.5 22 Dec 2021, 18:15 UTC

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

CVE-2021-43628 projectworlds vulnerability CVSS: 7.5 22 Dec 2021, 18:15 UTC

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.

CVE-2021-43158 projectworlds vulnerability CVSS: 4.3 22 Dec 2021, 18:15 UTC

In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.

CVE-2021-43157 projectworlds vulnerability CVSS: 7.5 22 Dec 2021, 18:15 UTC

Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.

CVE-2021-43156 projectworlds vulnerability CVSS: 4.3 22 Dec 2021, 18:15 UTC

In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.

CVE-2021-43155 projectworlds vulnerability CVSS: 7.5 22 Dec 2021, 18:15 UTC

Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.

CVE-2020-29205 projectworlds vulnerability CVSS: 4.3 17 May 2021, 19:15 UTC

XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field

CVE-2020-19114 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

CVE-2020-19113 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.

CVE-2020-19112 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.

CVE-2020-19111 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information.

CVE-2020-19110 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.

CVE-2020-19109 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code.

CVE-2020-19108 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.

CVE-2020-19107 projectworlds vulnerability CVSS: 7.5 06 May 2021, 13:15 UTC

SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

CVE-2020-27397 projectworlds vulnerability CVSS: 6.5 23 Dec 2020, 18:15 UTC

Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.

CVE-2020-25761 projectworlds vulnerability CVSS: 4.3 30 Sep 2020, 18:15 UTC

Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.

CVE-2020-25760 projectworlds vulnerability CVSS: 6.5 30 Sep 2020, 18:15 UTC

Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.

CVE-2020-23833 projectworlds vulnerability CVSS: 7.5 15 Sep 2020, 22:15 UTC

Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.

CVE-2020-24199 projectworlds vulnerability CVSS: 7.5 09 Sep 2020, 15:15 UTC

Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.

CVE-2020-24203 projectworlds vulnerability CVSS: 7.5 27 Aug 2020, 18:15 UTC

Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.

CVE-2020-24202 projectworlds vulnerability CVSS: 7.5 27 Aug 2020, 18:15 UTC

File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.

CVE-2020-11545 projectworlds vulnerability CVSS: 7.5 06 Apr 2020, 16:15 UTC

Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.

CVE-2020-11544 projectworlds vulnerability CVSS: 6.5 06 Apr 2020, 16:15 UTC

An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for executable files.