cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-7225,https://securityvulnerability.io/vulnerability/CVE-2024-7225,Cross Site Scripting Vulnerability in SourceCodester Insurance Management System 1.0,A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy of the component Edit Insurance Policy Page. The manipulation of the argument pname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272805 was assigned to this vulnerability.,SourceCodester,Insurance Management System,5.4,MEDIUM,0.000699999975040555,false,,false,false,false,,,false,false,,2024-07-30T09:15:00.000Z,0 CVE-2024-7080,https://securityvulnerability.io/vulnerability/CVE-2024-7080,Remote File Inclusion Vulnerability in SourceCodester Insurance Management System 1.0,"A vulnerability exists in the SourceCodester Insurance Management System version 1.0, associated with an unknown functionality within the /E-Insurance/ file. This flaw allows attackers to manipulate requests directly, exposing the system to potential remote exploitation. The vulnerability, which has been publicly disclosed, poses significant risks to data integrity and security. Users of the system are advised to apply relevant security measures to mitigate the risks associated with this flaw.",SourceCodester,Insurance Management System,7.5,HIGH,0.005330000072717667,false,,false,false,false,,,false,false,,2024-07-24T20:15:00.000Z,0 CVE-2024-7068,https://securityvulnerability.io/vulnerability/CVE-2024-7068,Cross Site Scripting Vulnerability in Insurance Management System 1.0,A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects an unknown part of the file /Script/admin/core/update_sub_category. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272349 was assigned to this vulnerability.,Sourcecodester,Insurance Management System,4.6,MEDIUM,0.0009500000160187483,false,,false,false,true,2024-07-24T14:00:08.000Z,true,false,false,,2024-07-24T15:00:08.622Z,0 CVE-2024-2150,https://securityvulnerability.io/vulnerability/CVE-2024-2150,File Inclusion Vulnerability in SourceCodester Insurance Management System,"A vulnerability has been identified in the SourceCodester Insurance Management System version 1.0 which allows for remote file inclusion due to improper handling of input parameters. This issue arises when the manipulation of the argument 'page' enables unauthorized access to sensitive files on the server, creating opportunities for attackers to exploit the system without direct access. The public disclosure of this exploit raises concerns regarding its potential use in the wild, emphasizing the importance of implementing robust security measures to protect against such vulnerabilities. Organizations using this software should prioritize remediating this issue to safeguard their systems and data.",Sourcecodester,Insurance Management System,5.3,MEDIUM,0.001180000021122396,false,,false,false,true,2024-03-03T18:00:06.000Z,true,false,false,,2024-03-03T18:00:06.251Z,0 CVE-2023-3693,https://securityvulnerability.io/vulnerability/CVE-2023-3693,SourceCodester Life Insurance Management System login.php sql injection,"A SQL injection vulnerability has been identified in the login.php file of SourceCodester's Life Insurance Management System 1.0. This flaw allows an attacker to manipulate the username argument, potentially leading to unauthorized access and manipulation of the database. Remote exploitation is possible, making systems using this application particularly vulnerable to attacks. Given that the exploit has been publicly disclosed, it is crucial for users to assess their security posture and apply necessary protections.",SourceCodester,Life Insurance Management System,9.8,CRITICAL,0.0021800000686198473,false,,false,false,false,,,false,false,,2023-07-16T22:15:00.000Z,0 CVE-2023-3165,https://securityvulnerability.io/vulnerability/CVE-2023-3165,SourceCodester Life Insurance Management System POST Parameter insertNominee.php cross site scripting,A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file insertNominee.php of the component POST Parameter Handler. The manipulation of the argument nominee_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231109 was assigned to this vulnerability.,Sourcecodester,Life Insurance Management System,3.5,LOW,0.0008800000068731606,false,,false,false,false,,,false,false,,2023-06-08T17:15:00.000Z,0