Billing System Project
Vendor:
First CVE: Sep 30, 2022 · Active for 3 years
5
Total CVEs
Bottom 1%
5.0
Avg CVEs / Year
Bottom 1%
8.2
Avg CVSS
Higher Avg CVSS than 88% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Billing System Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2022
3 years ago
Most Recent CVE
Nov 23, 2022
1,343 days ago
CVE Severity & Scoring
Billing System Project5 CVEs
60%
40%
All CVEs353,173 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High3 (60.0%)
None2 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43213CRITICAL Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. | Nov 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-43212CRITICAL Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php. | Nov 22, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-41437HIGH Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. | Sep 30, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-41440HIGH Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. | Sep 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-41439HIGH Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. | Sep 30, 2022 | 7.2 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Billing System Project
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 5 | 8.2 | 0.9% | 0 | 0 |