SCR-athif/CVE

SCR-athif/CVE

Releases0
Stars1
A curated list of CVEs uncovered through my dedicated research and hands-on exploration. These discoveries reflect my commitment to identifying vulnerabilities, understanding their impact, and contributing to improved security standards. Each entry highlights the depth of analysis and problem-solving that went into recognizing these threats.

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

5.4 MEDIUM

Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.

4.3 MEDIUM

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

6.1 MEDIUM

A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.

5.4 MEDIUM

A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.

5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.