Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Online Course Registration Project Subscribe
Filtered by product Online Course Registration
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-36064 1 Online Course Registration Project 1 Online Course Registration 2022-02-04 5.0 MEDIUM 9.8 CRITICAL
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
CVE-2020-23828 1 Online Course Registration Project 1 Online Course Registration 2020-09-21 7.5 HIGH 9.8 CRITICAL
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters. An attack uses /Online%20Course%20Registration/my-profile.php with the POST parameter photo.