The Lead Management System Project maintains a narrowly scoped application focused on lead capture and management functionality. Vulnerabilities affecting this product skew strongly toward critical-severity outcomes and center on SQL injection weaknesses in input handling, reflecting the application's reliance on database queries for core operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lead Management System Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4855CRITICAL A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. Affected is an unknown function of the file login.php. The manipulation o | Dec 30, 2022 | 9.8 | 41 | NO | NO |
CVE-2022-47864CRITICAL Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. | Jan 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47862CRITICAL Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. | Jan 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47861CRITICAL Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. | Jan 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47859CRITICAL Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php. | Jan 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47866CRITICAL Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. | Jan 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47865CRITICAL Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. | Jan 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47860CRITICAL Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. | Jan 11, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lead Management System Project.
Media articles that mention a CVE ID that affects a product developed by Lead Management System Project — matched by CVE ID, not by vendor name.