Vulnerabilities > Train Scheduler APP Project

DATE CVE VULNERABILITY TITLE RISK
2022-11-01 CVE-2022-43079 Cross-site Scripting vulnerability in Train Scheduler APP Project Train Scheduler APP 1.0
A cross-site scripting (XSS) vulnerability in /admin/add-fee.php of Train Scheduler App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.
network
low complexity
train-scheduler-app-project CWE-79
6.1
2022-10-31 CVE-2022-3774 Resource Injection vulnerability in Train Scheduler APP Project Train Scheduler APP 1.0
A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical.
network
low complexity
train-scheduler-app-project CWE-99
critical
9.1
2022-10-27 CVE-2022-42992 Cross-site Scripting vulnerability in Train Scheduler APP Project Train Scheduler APP 1.0
Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields.
network
low complexity
train-scheduler-app-project CWE-79
5.4