📦 Simple Online Bidding System

by Oretnom23

🔍 What is Simple Online Bidding System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-7797

HIGH CVSS 7.3 Aug 15, 2024

This CVE describes a critical SQL injection vulnerability in SourceCodester Simple Online Bidding System 1.0, allowing remote attackers to manipulate database queries via the username parameter in the...

CVE-2024-7911

MEDIUM CVSS 6.3 Aug 18, 2024

This vulnerability allows remote attackers to perform file inclusion attacks on SourceCodester Simple Online Bidding System 1.0 by manipulating the 'page' parameter in /simple-online-bidding-system/bi...

CVE-2024-7799

MEDIUM CVSS 5.3 Aug 15, 2024

CVE-2024-7799 is an improper authorization vulnerability in SourceCodester Simple Online Bidding System 1.0 that allows unauthorized access to admin functionality. Attackers can remotely exploit the /...

CVE-2024-6417

MEDIUM CVSS 6.3 Jun 30, 2024

This critical SQL injection vulnerability in Simple Online Bidding System 1.0 allows attackers to execute arbitrary SQL commands via the id parameter in the /admin/ajax.php?action=delete_user endpoint...

CVE-2024-5428

MEDIUM CVSS 4.3 May 28, 2024

This CSRF vulnerability in SourceCodester Simple Online Bidding System 1.0 allows attackers to trick authenticated administrators into performing unauthorized product management actions. Attackers can...

CVE-2024-4932

MEDIUM CVSS 6.3 May 16, 2024

This is a critical SQL injection vulnerability in SourceCodester Simple Online Bidding System 1.0 that allows attackers to manipulate database queries through the 'id' parameter in the admin interface...

CVE-2024-4930

MEDIUM CVSS 6.3 May 16, 2024

This critical SQL injection vulnerability in SourceCodester Simple Online Bidding System 1.0 allows attackers to manipulate database queries through the 'id' parameter in the view_prod page. Remote at...

CVE-2024-4928

MEDIUM CVSS 6.3 May 16, 2024

This is a critical SQL injection vulnerability in SourceCodester Simple Online Bidding System 1.0 that allows attackers to execute arbitrary SQL commands via the 'id' parameter in the admin/ajax.php e...