Vulnerabilities > Daily Tracker System Project

DATE CVE VULNERABILITY TITLE RISK
2020-09-09 CVE-2020-24194 Cross-site Scripting vulnerability in Daily Tracker System Project Daily Tracker System 1.0
A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.
4.3
2020-09-03 CVE-2020-24193 SQL Injection vulnerability in Daily Tracker System Project Daily Tracker System 1.0
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
network
low complexity
daily-tracker-system-project CWE-89
7.5