Vulnerabilities > Wedding Planner Project

DATE CVE VULNERABILITY TITLE RISK
2022-10-14 CVE-2022-41538 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-14 CVE-2022-41539 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-11 CVE-2022-42034 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-11 CVE-2022-42229 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-07 CVE-2022-42075 Unspecified vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 is vulnerable to arbitrary code execution.
network
low complexity
wedding-planner-project
critical
9.8
2022-09-26 CVE-2022-40483 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.
network
low complexity
wedding-planner-project CWE-89
critical
9.8
2022-09-26 CVE-2022-40484 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.
network
low complexity
wedding-planner-project CWE-89
critical
9.8
2022-09-26 CVE-2022-40485 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.
network
low complexity
wedding-planner-project CWE-89
critical
9.8
2022-09-26 CVE-2022-40402 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.
network
low complexity
wedding-planner-project CWE-89
8.8
2022-09-26 CVE-2022-40403 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
network
low complexity
wedding-planner-project CWE-89
7.2