Filtered by vendor Sourcecodester Subscriptions
Filtered by product Simple Library Management System Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-40402 1 Sourcecodester 1 Simple Library Management System 2024-11-21 6.3 Medium
A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries.
CVE-2024-40394 1 Sourcecodester 1 Simple Library Management System 2024-11-21 9.8 Critical
Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.