HOMEVULNERABILITIESVENDORSBadminton Center Management System Project

Badminton Center Management System ProjectCVEs & Vulnerabilities

22 CVEs affecting Badminton Center Management System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

badminton center management system 22
CVE-2022-31994HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=sales/view_details&id.

2 Jun 2022
7.2
CVSS
CVE-2022-31993CRITICAL

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.

2 Jun 2022
9.8
CVSS
CVE-2022-31992HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=court_rentals/view_court_rental&id=.

2 Jun 2022
7.2
CVSS
CVE-2022-31991CRITICAL

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_court.

2 Jun 2022
9.8
CVSS
CVE-2022-31990CRITICAL

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_product.

2 Jun 2022
9.8
CVSS
CVE-2022-31989CRITICAL

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=user/manage_user&id=.

2 Jun 2022
9.8
CVSS
CVE-2022-31988HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=reports/daily_services_report&date=.

2 Jun 2022
7.2
CVSS
CVE-2022-31986HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_court_rental_report&date=.

2 Jun 2022
7.2
CVSS
CVE-2022-31985HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_sales_report&date=.

2 Jun 2022
7.2
CVSS
CVE-2022-32006HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/services/view_service.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32005HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/services/manage_service.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32004HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/manage_product.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32003HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/view_court.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32002CRITICAL

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/manage_court.php?id=.

2 Jun 2022
9.8
CVSS
CVE-2022-32001HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/view_product.php?id=.

2 Jun 2022
7.2
CVSS
CVE-2022-32000HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/manage_service_transaction&id=.

2 Jun 2022
7.2
CVSS
CVE-2022-31998HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/view_details&id=.

2 Jun 2022
7.2
CVSS
CVE-2022-31996HIGH

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=sales/manage_sale&id=.

2 Jun 2022
7.2
CVSS
CVE-2022-30490CRITICAL

Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.

2 Jun 2022
9.8
CVSS
CVE-2022-30456MEDIUM

Badminton Center Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /bcms/classes/Master.php?f=save_court_rental.

24 May 2022
5.4
CVSS
CVE-2022-30455CRITICAL

Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.

24 May 2022
9.8
CVSS
CVE-2022-1817MEDIUM

A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

23 May 2022
5.4
CVSS
← PrevPage 1 / 1Next →
Badminton Center Management System Project CVEs & Vulnerabilities — 22 Tracked