Vulnerabilities > Oretnom23 > Budget AND Expense Tracker System

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2024-22628 SQL Injection vulnerability in Oretnom23 Budget and Expense Tracker System 1.0
Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=
network
low complexity
oretnom23 CWE-89
7.2
2023-05-17 CVE-2023-2772 Unspecified vulnerability in Oretnom23 Budget and Expense Tracker System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Budget and Expense Tracker System 1.0.
network
low complexity
oretnom23
8.8
2022-01-21 CVE-2021-40247 SQL Injection vulnerability in Oretnom23 Budget and Expense Tracker System 1.0
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
network
low complexity
oretnom23 CWE-89
critical
9.8
2021-10-29 CVE-2021-41645 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Budget and Expense Tracker System 1.0
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field.
network
low complexity
oretnom23 CWE-434
8.8