RSS   Vulnerabilities for 'Alumni management system'   RSS

2020-12-23
 
CVE-2020-28071

CWE-79
 

 
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.

 
 
CVE-2020-28070

CWE-89
 

 
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.

 
2020-12-15
 
CVE-2020-28072

CWE-434
 

 
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.

 


Copyright 2021, cxsecurity.com

 

Back to Top