Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Money Transfer Management System Project Subscribe
Filtered by product Money Transfer Management System
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44582 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-06-17 6.5 MEDIUM 8.8 HIGH
A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.
CVE-2022-29746 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.
CVE-2022-29739 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=user/manage_user&id=.
CVE-2022-29738 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=transaction/send&id=, id.
CVE-2022-29741 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_fee.
CVE-2022-29745 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction.
CVE-2022-25221 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-03-28 4.3 MEDIUM 6.1 MEDIUM
Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a user into visit the link in order to execute JavaScript code.
CVE-2022-25222 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-03-28 7.5 HIGH 9.8 CRITICAL
Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.
CVE-2022-25223 1 Money Transfer Management System Project 1 Money Transfer Management System 2022-03-28 4.0 MEDIUM 4.3 MEDIUM
Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter.