Vulnerabilities > Lopalopa

DATE CVE VULNERABILITY TITLE RISK
2024-12-09 CVE-2024-54929 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54936 Cross-site Scripting vulnerability in Lopalopa E-Learning Management System 1.0
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0.
network
low complexity
lopalopa CWE-79
5.4
2024-12-09 CVE-2024-54937 Unspecified vulnerability in Lopalopa E-Learning Management System 1.0
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.
network
low complexity
lopalopa
5.3
2024-11-14 CVE-2024-50823 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
network
low complexity
lopalopa CWE-89
critical
9.8
2024-11-14 CVE-2024-50824 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50825 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50826 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50827 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50828 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50829 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.
network
low complexity
lopalopa CWE-89
7.2