📦 Dino Physics School Assistant

by Dino Physics School Assistant Project

🔍 What is Dino Physics School Assistant?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-35349

CRITICAL CVSS 9.8 May 30, 2024

This vulnerability allows attackers to execute arbitrary SQL commands through the id parameter in the /admin/category/view_category.php file in Diño Physics School Assistant. This affects all users r...

CVE-2024-35353

CRITICAL CVSS 9.8 May 30, 2024

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Diño Physics School Assistant version 2.3. Attackers can manipulate the 'id' parameter in the /classes/Users.php?f=save ...

CVE-2024-35354

CRITICAL CVSS 9.8 May 30, 2024

This vulnerability allows attackers to execute arbitrary SQL commands through the id parameter in Diño Physics School Assistant. It affects all users of version 2.3 who have access to the vulnerable ...

CVE-2024-35351

MEDIUM CVSS 5.4 May 30, 2024

This vulnerability allows attackers to inject malicious scripts via the 'name' parameter in the /classes/SystemSettings.php?f=update_settings endpoint in Diño Physics School Assistant version 2.3. Wh...

CVE-2024-35345

MEDIUM CVSS 5.4 May 30, 2024

This vulnerability allows attackers to inject malicious scripts via the 'id' parameter in Diño Physics School Assistant, resulting in cross-site scripting (XSS). It affects users of version 2.3 who a...

CVE-2024-35356

MEDIUM CVSS 6.3 May 30, 2024

This vulnerability allows attackers to execute arbitrary SQL commands through the 'id' parameter in Diño Physics School Assistant version 2.3. Attackers can potentially read, modify, or delete databa...

CVE-2024-35358

MEDIUM CVSS 6.5 May 30, 2024

This vulnerability allows attackers to perform SQL injection attacks on Diño Physics School Assistant version 2.3 by manipulating the 'id' parameter in the /classes/Master.php?f=view_category endpoin...