Vulnerabilities (CVE)

Filtered by vendor Anisha Subscribe
Filtered by product Wazifa System
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-1208 1 Anisha 1 Wazifa System 2025-02-21 4.0 MEDIUM 3.5 LOW
A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /Profile.php. The manipulation of the argument postcontent leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-1209 1 Anisha 1 Wazifa System 2025-02-19 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. There is a typo in the affected file name.
CVE-2025-1210 1 Anisha 1 Wazifa System 2025-02-19 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is an unknown functionality of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12001 1 Anisha 1 Wazifa System 2024-12-10 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is an unknown function of the file /controllers/updatesettings.php of the component Setting Handler. The manipulation of the argument firstname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2024-10699 1 Anisha 1 Wazifa System 2024-11-05 7.5 HIGH 7.3 HIGH
A vulnerability was found in code-projects Wazifa System 1.0. It has been classified as critical. This affects an unknown part of the file /controllers/logincontrol.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-10742 1 Anisha 1 Wazifa System 2024-11-05 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in code-projects Wazifa System 1.0 and classified as critical. This issue affects some unknown processing of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.