📦

complaint_management_system

Vendor: codeastro

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 4 Remote Access
Total CVEs 7 Total Indexed
Avg. EPSS 0.52% Exploit Prob.
Latest CVE CVE-2024-46335 Nov 17

Security Vulnerability Index

Page 1 / 1
4.6 CVSS

PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.

EPSS: 0.20%
6.5 CVSS

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.

EPSS: 0.23%
6.1 CVSS

PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.

EPSS: 0.22%
6.5 CVSS

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php.

EPSS: 0.23%
6.5 CVSS

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php.

EPSS: 0.23%
8.8 CVSS

phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.

EPSS: 0.56%
7.2 CVSS

phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter.

EPSS: 0.58%
6.5 CVSS

phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid parameter.

EPSS: 0.40%
7.5 CVSS

A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.

EPSS: 0.45%
8.1 CVSS

phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.

EPSS: 0.41%