← Back

E Learning Management System

e-learning_management_system

Vendor: Lopalopa • 41 CVEs

CVEs (41)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id paramete...Show more
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id paramet...Show more
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and c...Show more
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via t...Show more
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, first...Show more
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts...Show more
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, las...Show more
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the sch...Show more
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the fi...Show more
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter...Show more
A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter.Show less
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Dec 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message...Show more
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.Show less