Vulnerabilities > Egavilanmedia > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-12-30 CVE-2020-29230 Cross-site Scripting vulnerability in Egavilanmedia User Registration and Login System With Admin Panel 1.0
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user.
4.3
2020-12-30 CVE-2020-29228 SQL Injection vulnerability in Egavilanmedia User Registration and Login System With Admin Panel 1.0
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
network
low complexity
egavilanmedia CWE-89
5.0
2020-12-23 CVE-2020-35252 Cross-site Scripting vulnerability in Egavilanmedia User Registration and Login System With Admin Panel 1.0
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
4.3
2020-12-21 CVE-2020-35273 Cross-Site Request Forgery (CSRF) vulnerability in Egavilanmedia User Registration & Login System With Admin Panel 1.0
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel.
6.0
2020-12-15 CVE-2020-35396 Cross-site Scripting vulnerability in Egavilanmedia Barcodes Generator 1.0
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php.
4.3
2020-12-15 CVE-2020-35395 Cross-site Scripting vulnerability in Egavilanmedia Expense Management System 1.0
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
4.3