Skip to main content

Vendor archive

lopalopa CVEs

Beta · best-effort

112 CVEs tagged to vendor lopalopa20 Critical, 35 High, 56 Medium, 1 Low, 0 Unrated.

CVE-2024-54938

Published Dec 9, 2024

A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54931

Published Dec 9, 2024

A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unautho…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-54925

Published Dec 9, 2024

A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauth…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-54924

Published Dec 9, 2024

A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unautho…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-54923

Published Dec 9, 2024

A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-54921

Published Dec 9, 2024

A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorize…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-54935

Published Dec 9, 2024

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remot…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54922

Published Dec 9, 2024

A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthoriz…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54926

Published Dec 9, 2024

A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54920

Published Dec 9, 2024

A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to ge…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-54919

Published Dec 9, 2024

A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54937

Published Dec 9, 2024

A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54936

Published Dec 9, 2024

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to exec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 112 CVEsPage 1 of 5