Simple Cold Storage Management System Project is a niche storage-management application whose vulnerability footprint centers on input-handling and validation defects typical of web-facing database applications, particularly SQL injection and cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simple Cold Storage Management System Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45253CRITICAL The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls | Dec 21, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-43229HIGH Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php. | Oct 28, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-43230HIGH Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details. | Oct 28, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-42230HIGH Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=. | Oct 11, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-3547MEDIUM A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /csms/admin/? | Oct 17, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Cold Storage Management System Project.
Media articles that mention a CVE ID that affects a product developed by Simple Cold Storage Management System Project — matched by CVE ID, not by vendor name.