Filtered by vendor Phpgurukul Subscriptions
Filtered by product User Registration And Login And User Management System Subscriptions
Total 6 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-50843 1 Phpgurukul 1 User Registration And Login And User Management System 2024-11-15 5.3 Medium
A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to access sensitive files and directories via /loginsystem/assets.
CVE-2024-48282 1 Phpgurukul 1 User Registration And Login And User Management System 2024-10-16 7.6 High
A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.
CVE-2024-48283 1 Phpgurukul 1 User Registration And Login And User Management System 2024-10-16 9.8 Critical
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.
CVE-2024-48279 1 Phpgurukul 1 User Registration And Login And User Management System 2024-10-16 7.6 High
A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.
CVE-2024-48280 1 Phpgurukul 1 User Registration And Login And User Management System 2024-10-16 7.6 High
A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.
CVE-2024-48278 1 Phpgurukul 1 User Registration And Login And User Management System 2024-10-16 5.5 Medium
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.