Codeastro
codeastro
109 CVEs • 28 products
Products (28)
Click to collapseToggle
Products (28)
Click to collapse
CVEs (109)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized...Show more |
1Codeastro 1Complaint Management System Apr 3, 2025 Jan 3, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component. |
1Codeastro 1Online Food Ordering System Apr 3, 2025 Dec 31, 2024 5.3 MEDIUM· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_users.php of the component Up...Show more |
1Codeastro 1Online Food Ordering System Apr 3, 2025 Dec 31, 2024 6.9 MEDIUM· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipula...Show more |
1Codeastro 1Simple Loan Management System Apr 3, 2025 Dec 30, 2024 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The ma...Show more |
1Codeastro 1Car Rental System Mar 5, 2025 Dec 27, 2024 5.3 MEDIUM· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bookingconfirm.php. The manipulation of the argument...Show more |
1Codeastro 1House Rental Management System Apr 3, 2025 Dec 26, 2024 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signin.php. The manipulation of the argument u/p...Show more |
1Codeastro 1House Rental Management System Apr 3, 2025 Dec 26, 2024 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ownersignup.php. The manipulation of th...Show more |
1Codeastro 1Blood Donor Management System May 14, 2025 Dec 26, 2024 5.3 MEDIUM· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id...Show more |
1Codeastro 1Complaint Management System Apr 3, 2025 Dec 20, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component. |
1Codeastro 1Complaint Management System Apr 3, 2025 Dec 18, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id p...Show more |
1Codeastro 1Complaint Management System Apr 17, 2025 Dec 18, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component. |
1Codeastro 1Real Estate Management System Dec 19, 2025 Nov 10, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /aboutedit.php of the component About Us Page. The man...Show more |
1Codeastro 1Real Estate Management System Jun 4, 2025 Nov 8, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. Th...Show more |
1Codeastro 1Real Estate Management System Jun 4, 2025 Nov 8, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the a...Show more |
1Codeastro 1Membership Management System Mar 31, 2025 Oct 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php |
1Codeastro 1Membership Management System Mar 31, 2025 Oct 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php. |
1Codeastro 1Membership Management System Mar 31, 2025 Sep 27, 2024 N/A· v4 8.6 HIGH· v3 N/A· v2 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. |
1Codeastro 1Membership Management System Mar 31, 2025 Sep 27, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information. |
1Codeastro 1Membership Management System Mar 31, 2025 Sep 27, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component. |