Filtered by vendor Travel Management System Project Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-25213 1 Travel Management System Project 1 Travel Management System 2024-11-21 9.8 Critical
SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php.
CVE-2021-25208 1 Travel Management System Project 1 Travel Management System 2024-11-21 9.8 Critical
Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php.
CVE-2024-51328 1 Travel Management System Project 1 Travel Management System 2024-11-04 6.1 Medium
Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.