Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Simple College Website Project Subscribe
Filtered by product Simple College Website
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-40089 1 Simple College Website Project 1 Simple College Website 2022-09-26 N/A 9.8 CRITICAL
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.
CVE-2022-40088 1 Simple College Website Project 1 Simple College Website 2022-09-26 N/A 6.1 MEDIUM
Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
CVE-2022-40087 1 Simple College Website Project 1 Simple College Website 2022-09-26 N/A 9.8 CRITICAL
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2021-44593 1 Simple College Website Project 1 Simple College Website 2022-02-03 6.8 MEDIUM 8.1 HIGH
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.
CVE-2021-26232 1 Simple College Website Project 1 Simple College Website 2021-07-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.