Online Course Registration ProjectCVEs & Vulnerabilities
2 CVEs affecting Online Course Registration Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
online course registration 2
CVE-2020-36064CRITICAL
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
31 Jan 2022
9.8
CVSS
CVE-2020-23828CRITICAL
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters. An attack uses /Online%20Course%20Registration/my-profile.php with the POST parameter photo.
16 Sep 2020
9.8
CVSS
← PrevPage 1 / 1Next →