ZeroHour

Vulnerabilities

24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36337
+1 in the same advisory: …36338
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrar

A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • inventory management system project inventory management system
CVE-2023-51813
Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

NVD description · AI analysis pending
6.5<1% PoC
  • free and open source inventory management system project free and open source inventory management system
CVE-2023-39712
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts o

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.

NVD description · AI analysis pending
6.1<1%
  • free and open source inventory management system project free and open source inventory management system
CVE-2023-39711
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts o

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

NVD description · AI analysis pending
6.1<1% PoC
  • free and open source inventory management system project free and open source inventory management system
CVE-2023-39714
+1 in the same advisory: …39710
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts o

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.

NVD description · AI analysis pending
6.1<1% PoC
  • free and open source inventory management system project free and open source inventory management system
CVE-2023-39709
+1 in the same advisory: …39708
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts o

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.

NVD description · AI analysis pending
6.1<1% PoC
  • free and open source inventory management system project free and open source inventory management system
CVE-2023-4558
+2 in the same advisory: …4557 …4555
A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0.

A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file staff_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238159.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • inventory management system project inventory management system
CVE-2023-39707
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or

A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.

NVD description · AI analysis pending
5.4<1% PoC
  • free and open source inventory management system project free and open source inventory management system
CVE-2023-4449
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0.

A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /index.php?page=member. The manipulation of the argument columns[0][data] leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-237570 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
8.8<1% PoC
  • inventory management system project inventory management system
CVE-2023-4436
+2 in the same advisory: …4437 …4438
A vulnerability, which was classified as critical, has been found in SourceCodester Inventory Management System 1.0.

A vulnerability, which was classified as critical, has been found in SourceCodester Inventory Management System 1.0. This issue affects some unknown processing of the file app/action/edit_update.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237557 was assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • inventory management system project inventory management system
CVE-2023-4184
+2 in the same advisory: …4182 …4183
A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical.

A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-236219.

NVD description · AI analysis pending
9.8<1%
  • inventory management system project inventory management system
CVE-2023-24234
+3 in the same advisory: …24233 …24232 …24231
A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers

A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.

NVD description · AI analysis pending
4.8<1%
  • inventory management system project inventory management system