The Money Transfer Management System Project maintains a specialized financial application whose vulnerability profile concentrates in a narrow product scope but carries outsized severity because flaws in payment systems directly threaten transaction integrity and account access. Its recurring exposure centers on web-layer input handling and access control, with durable weakness classes including SQL injection, forced browsing, and cross-site scripting that are characteristic of application-tier financial software and create direct paths to authentication bypass and data exfiltration. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Money Transfer Management System Project over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29745CRITICAL Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction. | May 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-29738CRITICAL Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=transaction/send&id=, id. | May 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-25222CRITICAL Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' vi | Mar 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-29746CRITICAL Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete. | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29741CRITICAL Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_fee. | May 12, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-44582HIGH A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin ro | Jun 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-29739CRITICAL Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=user/manage_user&id=. | May 12, 2022 | 9.8 | 24 | NO | NO |
CVE-2022-25221MEDIUM Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a user into visit the link in order to execute JavaScript code. | Mar 23, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-25223MEDIUM Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter. | Mar 23, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Money Transfer Management System Project.
Media articles that mention a CVE ID that affects a product developed by Money Transfer Management System Project — matched by CVE ID, not by vendor name.