Dasinfomedia develops a focused line of institutional management software spanning school administration, hospital operations, apartment facilities, and SMS gateway systems. The vulnerability profile centers on recurrent web-application and access-control weaknesses—SQL injection, unrestricted file upload, missing authorization, and authentication bypass—that are endemic to rapidly developed administrative platforms with legacy codebases. Public exploit code availability tends to be elevated for this vendor's disclosures, reflecting the appeal of these accessible management interfaces to opportunistic attackers; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dasinfomedia over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14847HIGH Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter. | Sep 28, 2017 | 8.8 | 39 | NO | YES |
CVE-2017-14848HIGH WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter. | Oct 3, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14846HIGH Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14845HIGH Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14844HIGH Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14843HIGH Mojoomla School Management System for WordPress allows SQL Injection via the id parameter. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14842HIGH Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14841MEDIUM Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling. | Sep 28, 2017 | 6.5 | 31 | NO | YES |
CVE-2024-9659CRITICAL The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload( | Nov 23, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-9658HIGH The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due | Mar 7, 2025 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dasinfomedia.
Media articles that mention a CVE ID that affects a product developed by Dasinfomedia — matched by CVE ID, not by vendor name.