thehackingverse

2 exploits Active since Oct 2022
CVE-2023-2594 NOMISEC HIGH STUB
Food Ordering Management System 1.0 - SQL Injection via Registration Username Parameter
A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the component Registration. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-228396.
1 stars
CVSS 7.3
CVE-2022-3546 NOMISEC LOW STUB
SourceCodester Simple Cold Storage Management System 1.0 - XSS
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /csms/admin/?page=user/list of the component Create User Handler. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-211046 is the identifier assigned to this vulnerability.
CVSS 2.4