Known Vulnerabilities for School Event Management System by School Event Management System Project
Listed below are 3 of the newest known vulnerabilities associated with "School Event Management System" by "School Event Management System Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-18795 json | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | 9.8 - CRITICAL | 2018-11-16 | 2018-12-18 |
| CVE-2018-18794 json | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. | 8.8 - HIGH | 2018-11-16 | 2018-12-18 |
| CVE-2018-18793 json | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. | 9.8 - CRITICAL | 2018-11-16 | 2018-12-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | School Event Management System Project | School Event Management System | 1.0 |