Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Expense Management System Project Subscribe
Filtered by product Expense Management System
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41434 1 Expense Management System Project 1 Expense Management System 2022-09-29 N/A 5.4 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.
CVE-2022-2688 1 Expense Management System Project 1 Expense Management System 2022-08-11 N/A 9.8 CRITICAL
A vulnerability was found in SourceCodester Expense Management System. It has been rated as critical. This issue affects the function fetch_report_credit of the file report.php of the component POST Parameter Handler. The manipulation of the argument from/to leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-205811.