Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sentinal920

#17715of 53,608
15.2Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2022-11860
5.4
2022-03-31
Unknown · Sourcecodester Simple Client Management System · CVE-2021-43505
**Name of the Vulnerable Software and Affected Versions** Ssourcecodester Simple Client Management System version 1 **Description** Multiple Cross Site Scripting (XSS) vulnerabilities exist in the system via the `Add new Client` and `Add new invoice` features. **Recommendations** For Ssourcecodester Simple Client Management System version 1, consider disabling the `Add new Client` and `Add new invoice` features until a patch is available to prevent potential exploitation. Restrict access to these features to minimize the risk of XSS attacks.
PT-2022-11861
9.8
2022-03-31
Unknown · Sourcecodester Simple Client Management System · CVE-2021-43506
**Name of the Vulnerable Software and Affected Versions** Sourcecodester Simple Client Management System version 1.0 **Description** An SQL Injection issue exists via the `password` parameter in Login.php. This allows for potential exploitation. **Recommendations** For Sourcecodester Simple Client Management System version 1.0, consider restricting access to the Login.php file until a patch is available. As a temporary workaround, avoid using the `password` parameter in the affected login functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.