← Back

Salonerp Project

salonerp_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Salonerp
salonerp

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Salonerp Project
1Salonerp
Jun 17, 2026
Nov 3, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
1Salonerp Project
1Salonerp
Jun 17, 2026
Jan 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be d...Show more
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.Show less