Записи SourceCodester
12 опубликованных записей вендора sourcecodester.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-28303Эксплойта нет | Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/iCWE-89 | Критическая9,8 | — | 0,5 % | 19 мар. 2024 г. |
36Наблюдать | CVE-2019-18417Эксплойта нет | Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code executionsourcecodester · restaurant management system · CWE-434 | Высокая8,8 | — | 1,7 % | 24 окт. 2019 г. |
36Наблюдать | CVE-2024-33294Эксплойта нет | An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variableCWE-94 | Критическая9,1 | — | 0,7 % | 6 мая 2024 г. |
35Наблюдать | CVE-2019-18414Эксплойта нет | Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lacsourcecodester · restaurant management system · CWE-352 | Высокая8,8 | — | 0,5 % | 24 окт. 2019 г. |
29Наблюдать | CVE-2024-33306Эксплойта нет | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.sourcecodester · laboratory management system · CWE-79 | Высокая7,4 | — | 0,7 % | 1 мая 2024 г. |
28Наблюдать | CVE-2024-34231Эксплойта нет | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scrsourcecodester · laboratory management system · CWE-79 | Высокая7,1 | — | 0,5 % | 14 мая 2024 г. |
25Наблюдать | CVE-2024-51430Proof of concept | Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary CWE-79 | Средняя6,4 | — | 0,6 % | 31 окт. 2024 г. |
24Наблюдать | CVE-2021-41728Эксплойта нет | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.sourcecodester · news247 cms · CWE-79 | Средняя6,1 | — | 0,6 % | 28 окт. 2021 г. |
24Наблюдать | CVE-2024-34230Эксплойта нет | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scrsourcecodester · laboratory management system · CWE-79 | Средняя6,1 | — | 0,5 % | 14 мая 2024 г. |
24Наблюдать | CVE-2024-33305Эксплойта нет | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.sourcecodester · laboratory management system · CWE-79 | Средняя6,1 | — | 0,4 % | 2 мая 2024 г. |
22Наблюдать | CVE-2025-6160Эксплойта нет | SourceCodester Client Database Management System user_customer_create_order.php sql injectionsourcecodester · downloading client database management system · CWE-74 | Средняя5,5 | — | 0,6 % | 17 июн. 2025 г. |
21Наблюдать | CVE-2024-33307Эксплойта нет | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.sourcecodester · laboratory management system · CWE-79 | Средняя5,4 | — | 0,4 % | 1 мая 2024 г. |
- CVE-2024-2830339Наблюдать
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/i
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %19 мар. 2024 г.
- CVE-2019-1841736Наблюдать
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sourcecodester · restaurant management system24 окт. 2019 г.
- CVE-2024-3329436Наблюдать
An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %6 мая 2024 г.
- CVE-2019-1841435Наблюдать
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lac
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sourcecodester · restaurant management system24 окт. 2019 г.
- CVE-2024-3330629Наблюдать
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %sourcecodester · laboratory management system1 мая 2024 г.
- CVE-2024-3423128Наблюдать
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scr
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %sourcecodester · laboratory management system14 мая 2024 г.
- CVE-2024-5143025Наблюдать
Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary
СредняяCVSS 6,4Proof of conceptEPSS 1 %31 окт. 2024 г.
- CVE-2021-4172824Наблюдать
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sourcecodester · news247 cms28 окт. 2021 г.
- CVE-2024-3423024Наблюдать
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scr
СредняяCVSS 6,1Эксплойта нетEPSS 0 %sourcecodester · laboratory management system14 мая 2024 г.
- CVE-2024-3330524Наблюдать
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %sourcecodester · laboratory management system2 мая 2024 г.
- CVE-2025-616022Наблюдать
SourceCodester Client Database Management System user_customer_create_order.php sql injection
СредняяCVSS 5,5Эксплойта нетEPSS 1 %sourcecodester · downloading client database management system17 июн. 2025 г.
- CVE-2024-3330721Наблюдать
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %sourcecodester · laboratory management system1 мая 2024 г.