The Institutional Management Website Project develops a web-based platform for institutional administration, with disclosed vulnerabilities centered on input-handling defects in web applications: SQL injection and improper file-upload validation recur as the primary weakness classes observed. Treat this as a focused vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Institutional Management Website Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45527CRITICAL File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory. | Feb 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-45526CRITICAL SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_tra | Feb 8, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Institutional Management Website Project.
Media articles that mention a CVE ID that affects a product developed by Institutional Management Website Project — matched by CVE ID, not by vendor name.