Vulnerabilities (CVE)

Filtered by CWE-89
Total 15229 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41679 1 Os4ed 1 Opensis 2024-11-21 6.8 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.
CVE-2021-41678 1 Os4ed 1 Opensis 2024-11-21 6.8 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.
CVE-2021-41677 1 Os4ed 1 Opensis 2024-11-21 6.8 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.
CVE-2021-41676 1 Pharmacy Point Of Sale System Project 1 Pharmacy Point Of Sale System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
CVE-2021-41674 1 E-negosyo System Project 1 E-negosyo System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.
CVE-2021-41672 1 Peel 1 Peel Shopping 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database.
CVE-2021-41662 1 South Gate Inn Online Reservation System Project 1 South Gate Inn Online Reservation System 2024-11-21 7.5 HIGH 9.8 CRITICAL
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution.
CVE-2021-41661 1 Church Management System Project 1 Church Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
CVE-2021-41660 1 Patient Appointment Scheduler System Project 1 Patient Appointment Scheduler System 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
CVE-2021-41659 1 Banking System Project 1 Banking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.
CVE-2021-41654 1 Wuzhicms 1 Wuzhicms 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
CVE-2021-41651 1 Hotel Management System Project 1 Hotel Management System 2024-11-21 5.0 MEDIUM 7.5 HIGH
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.
CVE-2021-41649 1 Online-shopping-system-advanced Project 1 Online-shopping-system-advanced 2024-11-21 7.5 HIGH 9.8 CRITICAL
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
CVE-2021-41648 1 Online-shopping-system-advanced Project 1 Online-shopping-system-advanced 2024-11-21 5.0 MEDIUM 7.5 HIGH
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
CVE-2021-41647 1 Online Food Ordering Web App Project 1 Online Food Ordering Web App 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
CVE-2021-41609 1 Classapps 1 Selectsurvey.net 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.
CVE-2021-41511 1 Lodging Reservation Management System Project 1 Lodging Reservation Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
CVE-2021-41492 1 Simple Cashiering System Project 1 Simple Cashiering System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.
CVE-2021-41487 1 Nokia 1 Vitalsuite 2024-11-21 7.5 HIGH 9.8 CRITICAL
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
CVE-2021-41472 1 Simple Membership System Using Php And Ajax Project 1 Simple Membership System Using Php And Ajax 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.