Purchase Order Management ProjectCVEs & Vulnerabilities
3 CVEs affecting Purchase Order Management Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
purchase order management 3
CVE-2023-29623MEDIUM
Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.
14 Apr 2023
6.1
CVSS
CVE-2023-29622CRITICAL
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.
14 Apr 2023
9.8
CVSS
CVE-2023-29621HIGH
Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
14 Apr 2023
8.8
CVSS
← PrevPage 1 / 1Next →