Vulnerabilities > Phone Shop Sales Management System Project

DATE CVE VULNERABILITY TITLE RISK
2021-11-02 CVE-2021-36560 Forced Browsing vulnerability in Phone Shop Sales Management System Project Phone Shop Sales Management System 1.0
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.
network
low complexity
phone-shop-sales-management-system-project CWE-425
critical
9.8
2021-08-03 CVE-2021-36623 Unrestricted Upload of File with Dangerous Type vulnerability in Phone Shop Sales Management System Project Phone Shop Sales Management System 1.0
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
network
low complexity
phone-shop-sales-management-system-project CWE-434
critical
9.8
2021-07-30 CVE-2021-36624 SQL Injection vulnerability in Phone Shop Sales Management System Project Phone Shop Sales Management System 1.0
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
network
low complexity
phone-shop-sales-management-system-project CWE-89
critical
9.8
2021-07-01 CVE-2021-35337 Authorization Bypass Through User-Controlled Key vulnerability in Phone Shop Sales Management System Project Phone Shop Sales Management System 1.0
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR).
4.3