← Back

Alumni Management System Project

alumni_management_system_project

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Jun 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Dec 23, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the descri...Show more
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.Show less
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Dec 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Dec 15, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.