HOMEVULNERABILITIESVENDORSSimple Client Management System Project

Simple Client Management System ProjectCVEs & Vulnerabilities

19 CVEs affecting Simple Client Management System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

simple client management system 19
CVE-2021-43657MEDIUM

A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.

22 Dec 2022
5.4
CVSS
CVE-2022-29984CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.

12 May 2022
9.8
CVSS
CVE-2022-29983CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.

12 May 2022
9.8
CVSS
CVE-2022-29982CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=.

12 May 2022
9.8
CVSS
CVE-2022-29981CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.

12 May 2022
9.8
CVSS
CVE-2022-29980CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=.

12 May 2022
9.8
CVSS
CVE-2022-29979CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.

12 May 2022
9.8
CVSS
CVE-2022-29751CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.

12 May 2022
9.8
CVSS
CVE-2022-29750CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.

12 May 2022
9.8
CVSS
CVE-2022-29749CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.

12 May 2022
9.8
CVSS
CVE-2022-29748CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.

12 May 2022
9.8
CVSS
CVE-2022-29747CRITICAL

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.

12 May 2022
9.8
CVSS
CVE-2021-43484CRITICAL

A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.

31 Mar 2022
9.8
CVSS
CVE-2021-43506CRITICAL

An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

31 Mar 2022
9.8
CVSS
CVE-2021-43505MEDIUM

Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

31 Mar 2022
5.4
CVSS
CVE-2022-26285CRITICAL

Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

22 Mar 2022
9.8
CVSS
CVE-2022-26284CRITICAL

Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

22 Mar 2022
9.8
CVSS
CVE-2021-43510CRITICAL

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

1 Feb 2022
9.8
CVSS
CVE-2021-43509CRITICAL

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.

1 Feb 2022
9.8
CVSS
← PrevPage 1 / 1Next →
Simple Client Management System Project CVEs & Vulnerabilities — 19 Tracked