Vulnerabilities > Online Sports Complex Booking System Project > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-05-19 CVE-2022-29652 SQL Injection vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client.
6.1
2022-04-25 CVE-2022-28094 Cross-site Scripting vulnerability in Online Sports Complex Booking System Project Online Sports Complex Booking System 1.0
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
4.3