Filtered by vendor Kostasmitroglou Subscriptions
Filtered by product Password Management Application Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-25346 1 Kostasmitroglou 2 Password Management Application, Thesystem 2026-02-27 7.1 High
TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1 to retrieve unauthorized database records and potentially access sensitive system information.
CVE-2019-25347 1 Kostasmitroglou 2 Password Management Application, Thesystem 2026-02-27 7.1 High
thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts.