Vulnerabilities > Lopalopa

DATE CVE VULNERABILITY TITLE RISK
2024-12-09 CVE-2024-54922 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54930 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54933 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54935 Cross-site Scripting vulnerability in Lopalopa E-Learning Management System 1.0
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0.
network
low complexity
lopalopa CWE-79
5.4
2024-12-09 CVE-2024-54926 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.
network
low complexity
lopalopa CWE-89
8.8
2024-12-09 CVE-2024-54919 Cross-site Scripting vulnerability in Lopalopa E-Learning Management System 1.0
A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0.
network
low complexity
lopalopa CWE-79
5.4
2024-12-09 CVE-2024-54920 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.
network
low complexity
lopalopa CWE-89
critical
9.8
2024-12-09 CVE-2024-54929 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54936 Cross-site Scripting vulnerability in Lopalopa E-Learning Management System 1.0
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0.
network
low complexity
lopalopa CWE-79
5.4
2024-12-09 CVE-2024-54937 Unspecified vulnerability in Lopalopa E-Learning Management System 1.0
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.
network
low complexity
lopalopa
5.3