Filtered by vendor Oretnom23
Subscribe
Total
650 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-6869 | 1 Oretnom23 | 1 Simple Company Website | 2025-07-08 | 5.8 MEDIUM | 4.7 MEDIUM |
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/testimonials/manage.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-6867 | 1 Oretnom23 | 1 Simple Company Website | 2025-07-08 | 5.8 MEDIUM | 4.7 MEDIUM |
A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-6868 | 1 Oretnom23 | 1 Simple Company Website | 2025-07-08 | 5.8 MEDIUM | 4.7 MEDIUM |
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-6873 | 1 Oretnom23 | 1 Simple Company Website | 2025-07-01 | 5.8 MEDIUM | 4.7 MEDIUM |
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-6872 | 1 Oretnom23 | 1 Simple Company Website | 2025-07-01 | 5.8 MEDIUM | 4.7 MEDIUM |
A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-6871 | 1 Oretnom23 | 1 Simple Company Website | 2025-07-01 | 7.5 HIGH | 7.3 HIGH |
A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-6870 | 1 Oretnom23 | 1 Simple Company Website | 2025-07-01 | 5.8 MEDIUM | 4.7 MEDIUM |
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Content.php?f=service. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2023-24654 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function. | |||||
CVE-2023-24656 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function. | |||||
CVE-2023-24364 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel. | |||||
CVE-2023-24652 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function. | |||||
CVE-2023-24729 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function. | |||||
CVE-2023-24653 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function. | |||||
CVE-2023-24730 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function. | |||||
CVE-2023-24651 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 5.4 MEDIUM |
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page. | |||||
CVE-2023-24731 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function. | |||||
CVE-2023-24655 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 9.8 CRITICAL |
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function. | |||||
CVE-2023-24728 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function. | |||||
CVE-2023-24732 | 1 Oretnom23 | 1 Simple Customer Relationship Management System | 2025-06-27 | N/A | 8.8 HIGH |
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function. | |||||
CVE-2025-6476 | 1 Oretnom23 | 1 Gym Management System | 2025-06-27 | 5.0 MEDIUM | 4.3 MEDIUM |
A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |