Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Plutoyrw

#20859of 57,490
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-91869
7.5
2026-09-15
Sourcecodester · Online Faculty Clearance System · CVE-2026-91004
**Name of the Vulnerable Software and Affected Versions** SourceCodester Online Faculty Clearance System version 1.0 **Description** A remote SQL injection is possible due to improper handling of the `ID` argument within a function in the `/delete faculty1.php` file. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-91874
6.5
2026-09-15
Sourcecodester · Online Faculty Clearance System · CVE-2026-91005
**Name of the Vulnerable Software and Affected Versions** SourceCodester Online Faculty Clearance System version 1.0 **Description** An unrestricted file upload issue exists in the Profile Picture Upload component within the `production/edit picture.php` file. A remote attacker can manipulate the `File` argument passed to the `move uploaded file()` function to upload arbitrary files to the server. **Recommendations** Update SourceCodester Online Faculty Clearance System version 1.0 to a version that addresses this issue. As a temporary mitigation, restrict access to the `production/edit picture.php` file or disable the Profile Picture Upload functionality.