📦 Wedding Management System

by Wedding Management System Project

🔍 What is Wedding Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-29656

CRITICAL CVSS 9.8 May 11, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the package_detail.php file via the id parameter. This allows attackers to execute arbitrary SQL commands on the database. Anyo...

CVE-2022-30831

HIGH CVSS 7.2 Jun 2, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the wedding_details.php file that allows attackers to execute arbitrary SQL commands. This affects all deployments of this spec...

CVE-2022-30833

HIGH CVSS 7.2 Jun 2, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the admin client editing interface. Attackers can manipulate database queries through the booking and user_id parameters, poten...

CVE-2022-30835

HIGH CVSS 7.2 Jun 2, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the budget.php admin endpoint that allows attackers to execute arbitrary SQL commands. This affects all deployments of this spe...

CVE-2022-30818

HIGH CVSS 7.2 Jun 2, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the blog_events_edit.php admin page that allows attackers to execute arbitrary SQL commands. This affects all deployments of We...

CVE-2022-30820

HIGH CVSS 8.8 Jun 2, 2022

CVE-2022-30820 is an arbitrary file upload vulnerability in Wedding Management v1.0 that allows attackers to upload malicious files through the picture upload functionality in users_edit.php. This can...

CVE-2022-30822

HIGH CVSS 8.8 Jun 2, 2022

Wedding Management System v1.0 contains an arbitrary file upload vulnerability in the users_profile.php picture upload function. This allows attackers to upload malicious files, potentially leading to...

CVE-2022-30825

HIGH CVSS 7.2 Jun 2, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the client_edit.php admin interface. This allows attackers to execute arbitrary SQL commands, potentially compromising the data...

CVE-2022-30827

HIGH CVSS 7.2 Jun 2, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the admin/package_edit.php endpoint. This allows attackers to execute arbitrary SQL commands on the database, potentially compr...

CVE-2022-30829

HIGH CVSS 7.2 Jun 2, 2022

Wedding Management System v1.0 contains a SQL injection vulnerability in the admin/users_edit.php endpoint that allows attackers to execute arbitrary SQL commands. This affects all deployments of this...