Vulnerabilities
16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-3988 | A vulnerability was found in Cafe Billing System 1.0. A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Order Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235609 was assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-27241 | SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client mod SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module. NVD description · AI analysis pending | 6.1 | <1% | PoC ×2 |
| — | |
| CVE-2022-43213 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-43212 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php. Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-43214 +1 in the same advisory: …43215 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-41504 | An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary co An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2022-41498 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2022-41437 | Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2022-2801 | A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206247. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-30461 +1 in the same advisory: …30462 | Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2020-36033 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php. SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2020-28183 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php. SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — |