Lucene search

K

Bank Management System Security Vulnerabilities

cve
cve

CVE-2024-5517

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file changepwd.php. The manipulation of the argument useremail leads to sql injection. The attack may be launched remotely......

7.3CVSS

7.7AI Score

0.0004EPSS

2024-05-30 03:15 PM
5
cve
cve

CVE-2024-5516

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file massage.php. The manipulation of the argument bid leads to sql injection. The attack can be launched remotely.....

6.3CVSS

7.3AI Score

0.0004EPSS

2024-05-30 02:15 PM
24
cve
cve

CVE-2024-33000

SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the...

3.5CVSS

7.1AI Score

0.0004EPSS

2024-05-14 04:17 PM
26
cve
cve

CVE-2024-0476

A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an unknown part of the file request-received-bydonar.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been...

4.8CVSS

4.9AI Score

0.001EPSS

2024-01-13 06:15 AM
15
cve
cve

CVE-2024-0459

A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to.....

7.2CVSS

7.3AI Score

0.001EPSS

2024-01-12 04:15 PM
4
cve
cve

CVE-2023-41575

Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address...

5.4CVSS

5.3AI Score

0.0004EPSS

2023-09-08 07:15 PM
13
cve
cve

CVE-2023-1964

A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack....

9.1CVSS

9.4AI Score

0.002EPSS

2023-04-09 09:15 AM
85
2
cve
cve

CVE-2023-1963

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated...

9.8CVSS

9.7AI Score

0.002EPSS

2023-04-09 08:15 AM
40
cve
cve

CVE-2023-0562

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched.....

9.8CVSS

9.6AI Score

0.065EPSS

2023-01-28 11:15 PM
42
cve
cve

CVE-2023-0563

A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate...

4.8CVSS

4.8AI Score

0.009EPSS

2023-01-28 11:15 PM
72
cve
cve

CVE-2022-4737

A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The...

9.8CVSS

9.7AI Score

0.002EPSS

2022-12-25 08:15 PM
27
cve
cve

CVE-2022-4738

A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is an unknown function of the file index.php?page=users of the component User Registration Handler. The manipulation of the argument Name leads to cross site scripting. It is...

6.1CVSS

6AI Score

0.001EPSS

2022-12-25 08:15 PM
30
cve
cve

CVE-2022-2087

A vulnerability, which was classified as problematic, was found in SourceCodester Bank Management System 1.0. This affects the file /mnotice.php?id=2. The manipulation of the argument notice with the input alert(1) leads to cross site scripting. It is possible to initiate the attack remotely. The.....

4.8CVSS

4.8AI Score

0.001EPSS

2022-06-15 01:15 PM
26
4
cve
cve

CVE-2022-2086

A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 union select 1,sleep(10),3,4,5 --+ leads to sql injection. The attack may be...

8.8CVSS

8.9AI Score

0.001EPSS

2022-06-15 01:15 PM
29
6
cve
cve

CVE-2022-26171

Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email...

9.8CVSS

9.8AI Score

0.002EPSS

2022-03-02 11:15 PM
58
cve
cve

CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery...

6.9CVSS

6.8AI Score

0.019EPSS

2020-04-29 09:15 PM
5272
In Wild
16
cve
cve

CVE-2019-11358

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native...

6.1CVSS

6.4AI Score

0.035EPSS

2019-04-20 12:29 AM
1198
In Wild
6