HOMEVULNERABILITIESVENDORSHome Owners Collection Management System Project

Home Owners Collection Management System ProjectCVEs & Vulnerabilities

15 CVEs affecting Home Owners Collection Management System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

home owners collection management system 15
CVE-2024-6440CRITICAL

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-270168.

2 Jul 2024
9.8
CVSS
CVE-2024-6439CRITICAL

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270167.

2 Jul 2024
9.8
CVSS
CVE-2022-28078MEDIUM

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

11 May 2022
6.1
CVSS
CVE-2022-28077MEDIUM

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

11 May 2022
6.1
CVSS
CVE-2022-28417CRITICAL

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.

21 Apr 2022
9.8
CVSS
CVE-2022-28416CRITICAL

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.

21 Apr 2022
9.8
CVSS
CVE-2022-28415CRITICAL

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection.

21 Apr 2022
9.8
CVSS
CVE-2022-28414CRITICAL

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member.

21 Apr 2022
9.8
CVSS
CVE-2022-25115HIGH

A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file.

3 Mar 2022
7.8
CVSS
CVE-2022-25045CRITICAL

Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

3 Mar 2022
9.8
CVSS
CVE-2022-25016CRITICAL

Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

2 Mar 2022
9.8
CVSS
CVE-2022-25028MEDIUM

Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.

1 Mar 2022
6.1
CVSS
CVE-2022-25096CRITICAL

Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.

26 Feb 2022
9.8
CVSS
CVE-2022-25095CRITICAL

Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.

26 Feb 2022
9.8
CVSS
CVE-2022-25094HIGH

Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.

26 Feb 2022
8.8
CVSS
← PrevPage 1 / 1Next →
Home Owners Collection Management System Project CVEs & Vulnerabilities — 15 Tracked