E Learning Management System

Vendor:

First CVE: Nov 14, 2024 · Active for 1 year

41
Total CVEs
More Total CVEs than 97% of tracked products
41.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact E Learning Management System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2024
20 months ago
Most Recent CVE
Dec 9, 2024
592 days ago

CVE Severity & Scoring

E Learning Management System41 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network41 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None31 (75.6%)
Unknown0 (0.0%)
Required10 (24.4%)
Privileges Required
Low10 (24.4%)
High18 (43.9%)
None13 (31.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthor
Dec 9, 20249.829NONO
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized
Dec 9, 20249.829NONO
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get
Dec 9, 20249.827NONO
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
Nov 14, 20249.827NONO
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
Dec 9, 20249.826NONO
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
Dec 9, 20249.826NONO
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthor
Dec 9, 20249.826NONO
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unautho
Dec 9, 20249.826NONO
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands t
Dec 9, 20249.826NONO
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
Dec 9, 20249.826NONO

Exploit Exposure

Signals from CVEs in this product scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (41 CVEs).

Media Mentions

Signals from CVEs in this product scope (41 CVEs).

Top CNAs Publishing CVEs For E Learning Management System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.0417.40.5%00