Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-37431 1 Darkseid 1 Beauty Parlour Management System 2026-05-11 9.8 Critical
Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
CVE-2025-26157 1 Darkseid 1 Beauty Parlour Management System 2025-06-06 5.9 Medium
A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.