📦

computer_laboratory_management_system

Vendor: oretnom23

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 3 Remote Access
Total CVEs 33 Total Indexed
Avg. EPSS 0.59% Exploit Prob.
Latest CVE CVE-2026-3770 Mar 08

Security Vulnerability Index

Page 1 / 4
2.1 CVSS

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.

EPSS: 0.21%
8.8 CVSS

A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter

EPSS: 0.43%
8.8 CVSS

SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.

EPSS: 0.50%
4.3 CVSS

SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php

EPSS: 0.74%
5.3 CVSS

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

EPSS: 0.59%
5.3 CVSS

A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file /classes/Master.php?f=delete_record. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

EPSS: 0.59%
5.3 CVSS

A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

EPSS: 0.59%
6.5 CVSS

Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.

EPSS: 0.60%
9.8 CVSS

SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.

EPSS: 0.60%
9.8 CVSS

SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.

EPSS: 0.70%