Products

Showing 2 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
amitkolloldey vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

elearning-script 1.0 - Authentication Bypass

E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit the /login.php file by sending a specific payload '=''or' to bypass authentication and gain unauthorized access to the system.

CWE-89Feb 12, 2026
CVSS8.8v4.0EPSS0.308%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

e-learning Php Script 0.1.0 - 'search' SQL Injection

e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information.

CWE-89Jan 30, 2026
CVSS8.8v4.0EPSS0.362%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX