📦 E Learning Management System

by Lopalopa

🔍 What is E Learning Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-54923

CRITICAL CVSS 9.8 Dec 9, 2024

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the department parameter in /admin/edit_teacher.php. This ena...

CVE-2024-54925

CRITICAL CVSS 9.8 Dec 9, 2024

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in /remove_sent_message.php. This enables un...

CVE-2024-54931

CRITICAL CVSS 9.8 Dec 9, 2024

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in the /admin/delete_event.php endpoint. Thi...

CVE-2024-54934

CRITICAL CVSS 9.8 Dec 9, 2024

Kashipara E-learning Management System v1.0 contains a SQL injection vulnerability in the delete_class.php admin endpoint. This allows attackers to execute arbitrary SQL commands, potentially compromi...

CVE-2024-54918

CRITICAL CVSS 9.8 Dec 9, 2024

Kashipara E-learning Management System v1.0 contains a remote code execution vulnerability in the teacher_avatar.php file upload functionality. Attackers can upload malicious files to execute arbitrar...

CVE-2024-54920

CRITICAL CVSS 9.8 Dec 9, 2024

A SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the teacher_signup.php endpoint. Attackers can gain unauthori...

CVE-2024-50833

CRITICAL CVSS 9.8 Nov 14, 2024

This SQL injection vulnerability in the KASHIPARA E-learning Management System login page allows attackers to execute arbitrary SQL commands through username and password fields. It affects all users ...

CVE-2024-54928

HIGH CVSS 7.2 Dec 9, 2024

This SQL injection vulnerability in kashipara E-learning Management System v1.0 allows attackers to execute arbitrary SQL commands via the /admin/delete_teacher.php endpoint. This affects all installa...

CVE-2024-54922

HIGH CVSS 7.2 Dec 9, 2024

This SQL injection vulnerability in kashipara E-learning Management System v1.0 allows remote attackers to execute arbitrary SQL commands through the firstname, lastname, and username parameters in th...

CVE-2024-54933

HIGH CVSS 7.2 Dec 9, 2024

CVE-2024-54933 is an SQL injection vulnerability in Kashipara E-learning Management System v1.0 that allows attackers to execute arbitrary SQL commands via the /admin/delete_content.php endpoint. This...

CVE-2024-54929

HIGH CVSS 7.2 Dec 9, 2024

KASHIPARA E-learning Management System v1.0 contains a SQL injection vulnerability in the delete_subject.php admin endpoint. This allows authenticated attackers to execute arbitrary SQL commands on th...

CVE-2024-50830

HIGH CVSS 7.2 Nov 14, 2024

A SQL injection vulnerability exists in the kashipara E-learning Management System Project 1.0, specifically in the /admin/calendar_of_events.php file via date_start, date_end, and title parameters. T...

CVE-2024-50824

HIGH CVSS 7.2 Nov 14, 2024

This SQL injection vulnerability in kashipara E-learning Management System allows attackers to execute arbitrary SQL commands through the class_name parameter in the admin/class.php endpoint. Attacker...

CVE-2024-50826

HIGH CVSS 7.2 Nov 14, 2024

This SQL injection vulnerability in kashipara E-learning Management System allows attackers to execute arbitrary SQL commands through the title and content parameters in the admin content addition pag...

CVE-2024-50828

HIGH CVSS 7.2 Nov 14, 2024

A SQL injection vulnerability in the kashipara E-learning Management System allows attackers to manipulate database queries through the 'd' parameter in the /admin/edit_department.php endpoint. This a...

CVE-2024-50835

HIGH CVSS 7.2 Nov 14, 2024

This SQL injection vulnerability in the KASHIPARA E-learning Management System allows attackers to manipulate database queries through the edit_student.php admin interface. Attackers could potentially...

CVE-2024-54937

MEDIUM CVSS 5.3 Dec 9, 2024

A directory listing vulnerability in Kashipara E-Learning Management System v1.0 allows remote attackers to browse sensitive files and directories via the /admin/assets path. This exposes potentially ...

CVE-2024-50837

MEDIUM CVSS 5.4 Nov 14, 2024

A stored cross-site scripting (XSS) vulnerability exists in the KASHIPARA E-learning Management System Project 1.0 admin interface. Attackers can inject malicious scripts via firstname and username pa...

CVE-2024-50839

MEDIUM CVSS 5.4 Nov 14, 2024

A stored cross-site scripting (XSS) vulnerability in KASHIPARA E-learning Management System Project 1.0 allows remote attackers to inject malicious scripts via subject_code and title parameters in the...

CVE-2024-50841

MEDIUM CVSS 5.4 Nov 14, 2024

A stored cross-site scripting vulnerability in KASHIPARA E-learning Management System Project allows attackers to inject malicious scripts into calendar event parameters. These scripts execute when ad...