Vulnerabilities
Vulnerable Software
Slims:  Security Vulnerabilities
Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/item_status.php.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-05-08
Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/author.php.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-05-08
Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-05-08
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
CVSS Score
7.2
EPSS Score
0.001
Published
2025-02-24
A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.
CVSS Score
6.7
EPSS Score
0.001
Published
2025-01-22
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
CVSS Score
4.9
EPSS Score
0.002
Published
2024-02-21
Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-12-01
SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-12-01
SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.
CVSS Score
8.8
EPSS Score
0.02
Published
2023-10-31
Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.
CVSS Score
9.9
EPSS Score
0.001
Published
2023-10-02


Contact Us

Shodan ® - All rights reserved