LeoZhangCA

3 exploits Active since May 2023
CVE-2023-2690 WRITEUP MEDIUM WRITEUP
SourceCodester Personnel Property Equipment System 1.0 - SQL Injection
A vulnerability, which was classified as critical, has been found in SourceCodester Personnel Property Equipment System 1.0. This issue affects some unknown processing of the file admin/returned_reuse_form.php of the component GET Parameter Handler. The manipulation of the argument client_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-228971.
CVSS 6.3
CVE-2023-2691 WRITEUP LOW WRITEUP
SourceCodester Personnel Property Equipment System 1.0 - XSS
A vulnerability, which was classified as problematic, was found in SourceCodester Personnel Property Equipment System 1.0. Affected is an unknown function of the file admin/add_item.php of the component POST Parameter Handler. The manipulation of the argument item_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228972.
CVSS 3.5
CVE-2023-2692 WRITEUP LOW WRITEUP
SourceCodester ICT Laboratory Management System 1.0 - XSS
A vulnerability has been found in SourceCodester ICT Laboratory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file views/room_info.php of the component GET Parameter Handler. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228973 was assigned to this vulnerability.
CVSS 3.5