amitkolloldey Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with amitkolloldey products.
Products
- e-learning PHP Script1 vulnerability
- elearning-script1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25320HIGH | elearning-script 1.0 - Authentication BypassE Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit the /login.php file by sending a specific payload '=''or' to bypass authentication and gain unauthorized access to the system. CWE-89Feb 12, 2026 | CVSS8.8v4.0 | EPSS0.308% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37035HIGH | e-learning Php Script 0.1.0 - 'search' SQL Injectione-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information. CWE-89Jan 30, 2026 | CVSS8.8v4.0 | EPSS0.362% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |