📦 School Event Management System

by Janobe

🔍 What is School Event Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-33974

CRITICAL CVSS 9.8 Aug 6, 2024

This SQL injection vulnerability in Janobe products allows attackers to execute arbitrary SQL queries through the 'Users' parameter in '/report/printlogs.php'. Attackers can potentially retrieve all d...

CVE-2024-33970

CRITICAL CVSS 9.8 Aug 6, 2024

A critical SQL injection vulnerability in the PayPal, Credit Card and Debit Card Payment module allows attackers to execute arbitrary SQL queries through the 'studid' parameter in '/candidate/controll...

CVE-2024-33972

CRITICAL CVSS 9.8 Aug 6, 2024

A critical SQL injection vulnerability in Janobe products' payment module allows attackers to execute arbitrary SQL queries through the '/report/event_print.php' endpoint. This affects systems running...

CVE-2024-33964

CRITICAL CVSS 9.8 Aug 6, 2024

A critical SQL injection vulnerability exists in the PayPal, Credit Card and Debit Card Payment module version 1.0, allowing attackers to execute arbitrary SQL queries through the 'id' parameter in '/...

CVE-2024-33966

CRITICAL CVSS 9.8 Aug 6, 2024

This is a critical SQL injection vulnerability in the payment module affecting version 1.0 of unspecified Janobe products. Attackers can exploit it to extract all database information through the 'xts...

CVE-2024-33968

CRITICAL CVSS 9.8 Aug 6, 2024

This SQL injection vulnerability in a payment module allows attackers to execute arbitrary SQL queries through the 'Attendance' and 'YearLevel' parameters. Attackers can potentially extract all databa...

CVE-2024-33962

CRITICAL CVSS 9.8 Aug 6, 2024

This CVE describes a critical SQL injection vulnerability in a payment module, allowing attackers to execute arbitrary SQL queries via a crafted 'code' parameter in an admin script. It affects version...

CVE-2024-33959

CRITICAL CVSS 9.8 Aug 6, 2024

This SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment version 1.0 allows attackers to execute arbitrary SQL queries through the 'categ' parameter in '/admin/mod_reports/printr...

CVE-2024-33991

HIGH CVSS 7.1 Aug 6, 2024

A Cross-Site Scripting (XSS) vulnerability in School Event Management System version 1.0 allows attackers to inject malicious scripts via the 'view' parameter in '/eventwinner/index.php'. This could e...

CVE-2024-33993

HIGH CVSS 7.1 Aug 6, 2024

This is a Cross-Site Scripting (XSS) vulnerability in School Event Management System version 1.0 that allows attackers to inject malicious scripts via the 'view' parameter in /candidate/index.php. Whe...

CVE-2024-33987

HIGH CVSS 7.1 Aug 6, 2024

This is a Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System version 1.0. An attacker can craft malicious URLs containing JavaScript pay...

CVE-2024-33989

HIGH CVSS 7.1 Aug 6, 2024

This is a Cross-Site Scripting (XSS) vulnerability in School Event Management System version 1.0 that allows attackers to inject malicious JavaScript via the 'eventdate' and 'events' parameters. When ...

CVE-2024-33983

HIGH CVSS 7.1 Aug 6, 2024

This is a Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System version 1.0. An attacker can craft malicious URLs containing JavaScript in ...

CVE-2024-33985

HIGH CVSS 7.1 Aug 6, 2024

This is a Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System version 1.0. An attacker can craft malicious URLs containing JavaScript in ...