A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-customer-services.php of the component Customer Detail Handler. The manipulation of the argument sids[] leads to sql injection.
This vulnerability is handled as CVE-2024-13072. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_users.php of the component Update User Page. The manipulation of the argument user_upd leads to sql injection.
This vulnerability is known as CVE-2024-13070. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/add-user.php. The manipulation of the argument name leads to cross site scripting.
This vulnerability is traded as CVE-2024-13069. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-13067. The attack may be initiated remotely. Furthermore, there is an exploit available.