Vulnerabilities (CVE)

Filtered by vendor Lopalopa Subscribe
Total 32 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-41239 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 4.8 MEDIUM
A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field.
CVE-2024-41242 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.
CVE-2024-41245 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 5.3 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.
CVE-2024-41244 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 5.3 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.
CVE-2024-41243 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 5.3 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.
CVE-2024-41246 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 5.3 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.
CVE-2024-41247 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 5.3 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry.
CVE-2024-41248 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 5.3 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.
CVE-2024-41249 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 5.3 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.
CVE-2024-41252 1 Lopalopa 1 Responsive School Management System 2024-08-08 N/A 6.5 MEDIUM
An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration.
CVE-2024-0307 1 Lopalopa 1 Dynamic Lab Management System 2024-05-17 7.5 HIGH 7.5 HIGH
A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249874 is the identifier assigned to this vulnerability.
CVE-2024-0306 1 Lopalopa 1 Dynamic Lab Management System 2024-05-17 7.5 HIGH 7.5 HIGH
A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249873 was assigned to this vulnerability.