Vulnerabilities
Vulnerable Software
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
CVSS Score
7.2
EPSS Score
0.001
Published
2025-02-24
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
CVSS Score
4.9
EPSS Score
0.002
Published
2024-02-21
SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.
CVSS Score
8.8
EPSS Score
0.02
Published
2023-10-31
Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.
CVSS Score
9.9
EPSS Score
0.001
Published
2023-10-02
Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php.
CVSS Score
6.1
EPSS Score
0.001
Published
2023-09-01
Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-09-01
SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-04-14
SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-12-05
Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.
CVSS Score
4.8
EPSS Score
0.001
Published
2022-11-01
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-11-01


Contact Us

Shodan ® - All rights reserved