CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oretnom23 1School Fees Management System Jun 17, 2026 Mar 21, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname...Show more |
1Oretnom23 1School Fees Management System Jun 17, 2026 Mar 21, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nam...Show more |
1Oretnom23 1School Fees Management System Jun 17, 2026 Mar 21, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name p...Show more |
1Oretnom23 1School Fees Management System Jun 17, 2026 Mar 21, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts...Show more |
1Oretnom23 1School Fees Management System Jun 17, 2026 Mar 21, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization. |
1Oretnom23 1School Fees Management System Jun 17, 2026 Mar 7, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname p...Show more |
1Oretnom23 1School Fees Management System Jun 17, 2026 Mar 7, 2024 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name paramet...Show more |