Vulnerabilities > Oretnom23 > Budget AND Expense Tracker System > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2024-22628 SQL Injection vulnerability in Oretnom23 Budget and Expense Tracker System 1.0
Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=
network
low complexity
oretnom23 CWE-89
7.2
2023-05-17 CVE-2023-2772 Unspecified vulnerability in Oretnom23 Budget and Expense Tracker System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Budget and Expense Tracker System 1.0.
network
low complexity
oretnom23
8.8
2021-10-29 CVE-2021-41645 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Budget and Expense Tracker System 1.0
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field.
network
low complexity
oretnom23 CWE-434
8.8