Filtered by vendor Amssplus Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-37141 2 Amss++ Project, Amssplus 2 Amss++, Amss Plus 2026-02-09 8.2 High
AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.
CVE-2020-37135 2 Amss++ Project, Amssplus 2 Amss++, Amss Plus 2026-02-09 7.5 High
AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.
CVE-2024-2589 2 Amss\+\+ Project, Amssplus 2 Amss\+\+, Amss Plus 2025-04-17 8.2 High
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_school_person.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.
CVE-2024-2586 2 Amss\+\+ Project, Amssplus 2 Amss\+\+, Amss Plus 2025-04-11 8.2 High
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/index.php, in the 'username' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.