CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Stock Management System Project 1Stock Management System Nov 21, 2024 Jun 6, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php. |
1Stock Management System Project 1Stock Management System Jun 20, 2025 Feb 5, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file. |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Nov 24, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request fo...Show more |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Nov 24, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads t...Show more |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Nov 24, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/pass...Show more |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Jan 31, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function. |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Sep 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.' |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter. |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Sep 2, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when the...Show more |
1Stock Management System Project 1Stock Management System Nov 21, 2024 Sep 1, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and session cookies when an u...Show more |