CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vishalmathur 1Institute Of Current Students Dec 12, 2025 Nov 20, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in SQL queries. |
1Vishalmathur 1Institute Of Current Students Oct 9, 2025 Jul 25, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability exists in Institute-of-Current-Students v1.0 via the email parameter in the /postquerypublic endpoint. The application fails to properly sanitize user input before ref...Show more |