Simple Client Management System
Vendor:
First CVE: Feb 1, 2022 · Active for 4 years
19
Total CVEs
More Total CVEs than 95% of tracked products
19.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
9.3
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Simple Client Management System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2022
4 years ago
Most Recent CVE
Dec 22, 2022
1,314 days ago
CVE Severity & Scoring
Simple Client Management System19 CVEs
11%
89%
All CVEs353,240 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (89.5%)
Unknown0 (0.0%)
Required2 (10.5%)
Privileges Required
Low2 (10.5%)
High0 (0.0%)
None17 (89.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43510CRITICAL SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. | Feb 1, 2022 | 9.8 | 45 | NO | YES |
CVE-2021-43484CRITICAL A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a req | Mar 31, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-26285CRITICAL Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the | Mar 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-29984CRITICAL Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=. | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29983CRITICAL Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=. | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29981CRITICAL Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete. | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29979CRITICAL Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation. | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29751CRITICAL Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client. | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29750CRITICAL Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service. | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29749CRITICAL Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice. | May 12, 2022 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Simple Client Management System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 19 | 9.3 | 2.0% | 0 | 1 |