Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Simple Client Management System Project Subscribe
Filtered by product Simple Client Management System
Total 19 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43657 1 Simple Client Management System Project 1 Simple Client Management System 2022-12-27 N/A 5.4 MEDIUM
A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.
CVE-2022-29749 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.
CVE-2022-29747 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.
CVE-2022-29748 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.
CVE-2022-29750 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.
CVE-2022-29751 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.
CVE-2022-29979 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.
CVE-2022-29981 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.
CVE-2022-29984 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.
CVE-2022-29982 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=.
CVE-2022-29983 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.
CVE-2022-29980 1 Simple Client Management System Project 1 Simple Client Management System 2022-05-18 7.5 HIGH 9.8 CRITICAL
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=.
CVE-2021-43484 1 Simple Client Management System Project 1 Simple Client Management System 2022-04-07 7.5 HIGH 9.8 CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.
CVE-2021-43505 1 Simple Client Management System Project 1 Simple Client Management System 2022-04-06 3.5 LOW 5.4 MEDIUM
Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.
CVE-2021-43506 1 Simple Client Management System Project 1 Simple Client Management System 2022-04-06 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.
CVE-2022-26285 1 Simple Client Management System Project 1 Simple Client Management System 2022-03-29 7.5 HIGH 9.8 CRITICAL
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
CVE-2022-26284 1 Simple Client Management System Project 1 Simple Client Management System 2022-03-29 7.5 HIGH 9.8 CRITICAL
Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
CVE-2021-43510 1 Simple Client Management System Project 1 Simple Client Management System 2022-02-04 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
CVE-2021-43509 1 Simple Client Management System Project 1 Simple Client Management System 2022-02-04 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.