Filtered by vendor Phpgurukul Subscriptions
Filtered by product Rail Pass Management System Subscriptions
Total 7 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-31935 1 Phpgurukul 1 Rail Pass Management System 2024-08-02 4.8 Medium
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php.
CVE-2023-31934 1 Phpgurukul 1 Rail Pass Management System 2024-08-02 4.8 Medium
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php.
CVE-2023-31936 1 Phpgurukul 1 Rail Pass Management System 2024-08-02 7.2 High
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file.
CVE-2023-31933 1 Phpgurukul 1 Rail Pass Management System 2024-08-02 7.2 High
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file.
CVE-2023-31937 1 Phpgurukul 1 Rail Pass Management System 2024-08-02 7.2 High
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file.
CVE-2023-31932 1 Phpgurukul 1 Rail Pass Management System 2024-08-02 7.2 High
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file.
CVE-2023-3275 1 Phpgurukul 1 Rail Pass Management System 2024-08-02 6.3 Medium
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability.