Filtered by vendor Lopalopa Subscriptions
Total 112 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-5214 1 Lopalopa 1 Responsive Online Learing Platform 2025-06-05 7.3 High
A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /courses/course_detail_user_new.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the affected product appears to have a typo in it.
CVE-2024-22917 1 Lopalopa 1 Dynamic Lab Management System 2025-05-08 8.6 High
SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.
CVE-2025-45322 1 Lopalopa 1 Online Service Management Portal 2025-05-07 8.8 High
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.
CVE-2025-45321 1 Lopalopa 1 Online Service Management Portal 2025-05-07 8.8 High
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.
CVE-2025-45320 1 Lopalopa 1 Online Service Management Portal 2025-05-07 7.5 High
A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.
CVE-2024-42789 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-05-06 6.3 Medium
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/controller.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter.
CVE-2024-42788 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-05-06 6.1 Medium
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "artist" parameter fields.
CVE-2024-42791 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-05-06 8.8 High
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.
CVE-2024-42787 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-05-06 6.1 Medium
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "description" parameter fields.
CVE-2024-50839 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2025-05-06 5.4 Medium
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters.
CVE-2024-50840 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2025-05-06 5.4 Medium
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter.
CVE-2024-50841 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2025-05-06 5.4 Medium
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters.
CVE-2024-50842 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2025-05-06 5.4 Medium
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the school_year parameter.
CVE-2024-50837 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2025-05-06 5.4 Medium
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and username parameters.
CVE-2024-50838 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2025-05-06 5.4 Medium
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the d and pi parameters.
CVE-2024-42797 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 9.8 Critical
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.
CVE-2024-42794 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 4.7 Medium
Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
CVE-2024-42795 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 4.2 Medium
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid user details.
CVE-2024-42796 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 5.9 Medium
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.
CVE-2024-42798 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 7.6 High
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.