Vulnerabilities
Vulnerable Software
Lead Management System Project:  Security Vulnerabilities
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-01-11
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-01-11
Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-01-11
A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-217020.
CVSS Score
7.3
EPSS Score
0.027
Published
2022-12-30


Contact Us

Shodan ® - All rights reserved