Vulnerabilities > Oretnom23

DATE CVE VULNERABILITY TITLE RISK
2022-09-05 CVE-2022-3122 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
A vulnerability was found in SourceCodester Clinics Patient Management System 1.0.
network
low complexity
oretnom23 CWE-89
critical
9.8
2022-09-05 CVE-2022-3120 Unspecified vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System.
network
low complexity
oretnom23
critical
9.8
2022-09-02 CVE-2022-36754 SQL Injection vulnerability in Oretnom23 Expense Management System 1.0
Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p.
network
low complexity
oretnom23 CWE-89
7.2
2022-09-02 CVE-2022-36609 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
network
low complexity
oretnom23 CWE-89
critical
9.8
2022-08-22 CVE-2022-36251 Cross-site Scripting vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.
network
low complexity
oretnom23 CWE-79
6.1
2022-08-17 CVE-2022-35117 Cross-site Scripting vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_medicine_details.php.
network
low complexity
oretnom23 CWE-79
4.8
2022-08-16 CVE-2022-36242 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
network
low complexity
oretnom23 CWE-89
critical
9.8
2022-08-10 CVE-2022-36270 Unspecified vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
network
low complexity
oretnom23
critical
9.8
2022-08-10 CVE-2022-36750 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.
network
low complexity
oretnom23 CWE-89
critical
9.8
2022-07-12 CVE-2022-2297 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Clinic'S Patient Management System 2.0
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0.
network
low complexity
oretnom23 CWE-434
8.8