Vulnerabilities
56 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-7912 +1 in the same advisory: …7910 | A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/assets/. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 6.9 group max | <1% | PoC |
| — | |
| CVE-2024-7815 +1 in the same advisory: …7814 | A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin-update-employee.php of the component Update Employee Page. The manipulation of the argument emp_fname /emp_lname /emp_nat_idno/emp_addr leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.1 | 1% | PoC |
| — | |
| CVE-2024-29806 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reservation Diary ReDi Restaurant Reservation allows Refle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reservation Diary ReDi Restaurant Reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2024-0782 | A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file pass-profile.php. The manipulation of the argument First Name/Last Name/User Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251698 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-43458 | Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the room, name, and description parameters in the manage_room function. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-24397 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions. Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2023-4193 +1 in the same advisory: …4192 | A vulnerability has been found in SourceCodester Resort Reservation System 1.0 and classified as critical. A vulnerability has been found in SourceCodester Resort Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_fee.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-236236. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-4191 | A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-236234 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-3309 | A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file ?page=rooms of the component Manage Room Page. The manipulation of the argument Cottage Number leads to cross site scripting. The attack can be launched remotely. The identifier VDB-231805 was assigned to this vulnerability. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-2824 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-2363 +1 in the same advisory: …2364 | A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This issue affects some unknown processing of the file view_room.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227639. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-1100 | A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This affects an unknown part of the file /reservation/add_message.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222003. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-1037 +1 in the same advisory: …1036 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /APR/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221795. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-1030 | A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2022-2754 +1 in the same advisory: …2753 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks NVD description · AI analysis pending | 9.8 group max | 38% | PoC |
| — | |
| CVE-2020-36553 | Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.p Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php. NVD description · AI analysis pending | 5.4 | 1% | PoC ×3 |
| — | |
| CVE-2022-33060 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2022-33056 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2021-41662 | The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2022-30481 | Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters. Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2022-28001 +1 in the same advisory: …28002 | Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter. Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter. NVD description · AI analysis pending | 9.8 group max | 2% | PoC ×2 |
| — | |
| CVE-2021-41471 | SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via t SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-46308 | An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter. An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2021-44091 | A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phon A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters. NVD description · AI analysis pending | 5.4 | <1% | PoC ×2 |
| — | |
| CVE-2021-42667 | A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server. NVD description · AI analysis pending | 9.8 group max | 16% | PoC ×2 |
| — | |
| CVE-2021-41511 | The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication. NVD description · AI analysis pending | 9.8 | 3% | PoC ×5 |
| — | |
| CVE-2021-38758 +1 in the same advisory: …38752 | Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php. Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php. NVD description · AI analysis pending | 7.5 group max | 2% | PoC ×2 |
| — | |
| CVE-2020-36002 | Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information. Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — |