Vulnerabilities
Vulnerable Software
Barangay Management System Project:  Security Vulnerabilities
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Contact Number parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-02-14
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-02-14
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-10-28
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-08-18
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php.
CVSS Score
8.8
EPSS Score
0.001
Published
2022-07-28
Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php.
CVSS Score
7.2
EPSS Score
0.267
Published
2022-07-27
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-07-20
Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.
CVSS Score
7.2
EPSS Score
0.003
Published
2022-07-19
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-07-19


Contact Us

Shodan ® - All rights reserved