ZeroHour

Vulnerabilities

19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-43657
A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to injec

A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.

NVD description · AI analysis pending
5.4<1%
  • simple client management system project simple client management system
CVE-2022-29984
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.

NVD description · AI analysis pending
9.82% PoC
  • simple client management system project simple client management system
CVE-2021-43484
+2 in the same advisory: …43506 …43505
A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file

A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.

NVD description · AI analysis pending
9.8
group max
4%
  • simple client management system project simple client management system
CVE-2022-26285
+1 in the same advisory: …26284
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint.

Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

NVD description · AI analysis pending
9.82% PoC
  • simple client management system project simple client management system
CVE-2021-43510
+1 in the same advisory: …43509
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

NVD description · AI analysis pending
9.88% PoC ×2
  • simple client management system project simple client management system