Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Insurance Management System — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Insurance Management System, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses affecting the Insurance Management System product, categorized by common vulnerability types and internal tracking tags. It aggregates publicly reported and vendor-disclosed security issues to provide a comprehensive overview of the product's exposure landscape. The collection encompasses a wide range of vulnerability classes, including injection flaws, broken access control, security misconfigurations, and cross-site scripting issues, covering disclosure events from early 2020 through mid-2024. This historical window captures both immediate post-release defects and long-term architectural gaps identified during routine audits. By centralizing this data, the page enables security professionals and risk managers to track a vendor’s advisory timeline and patch deployment speed. Users can also gain a deeper understanding of specific weakness classes by observing how they manifest within the complex logic of insurance processing workflows. Additionally, the resource allows for the lookup of a product's vulnerability history, facilitating trend analysis and regression testing. This structured approach supports informed decision-making regarding third-party risk assessment and compliance verification. The aggregation prioritizes accuracy and context over volume, ensuring that each entry provides actionable insight into the nature of the flaw and its potential impact on sensitive policyholder data. Ultimately, this resource serves as a neutral, factual reference point for evaluating the security posture of the Insurance Management System without speculation or subjective evaluation.

Vendor: SourceCodester

CVE IDTitleCVSSSeverityPublished
CVE-2025-8135 itsourcecode Insurance Management System updateAgent.php sql injection CWE-89 6.3 Medium2025-07-25
CVE-2025-7905 itsourcecode Insurance Management System insertPayment.php sql injection CWE-89 6.3 Medium2025-07-20
CVE-2025-7904 itsourcecode Insurance Management System insertNominee.php sql injection CWE-89 6.3 Medium2025-07-20
CVE-2025-7212 itsourcecode Insurance Management System insertAgent.php sql injection CWE-89 6.3 Medium2025-07-09
CVE-2024-8414 SourceCodester Insurance Management System cross-site request forgery CWE-352 4.3 Medium2024-09-04
CVE-2024-8216 nafisulbari/itsourcecode Insurance Management System Payment editPayment.php access control CWE-284 5.4 Medium2024-08-27
CVE-2024-8209 nafisulbari/itsourcecode Insurance Management System addClient.php cross site scripting CWE-79 3.5 Low2024-08-27
CVE-2024-8208 nafisulbari/itsourcecode Insurance Management System editClient.php cross site scripting CWE-79 3.5 Low2024-08-27
CVE-2024-7916 nafisulbari/itsourcecode Insurance Management System Add Nominee Page addNominee.php cross site scripting CWE-79 3.5 Low2024-08-18
CVE-2024-7225 SourceCodester Insurance Management System Edit Insurance Policy Page update_policy cross site scripting CWE-79 3.5 Low2024-07-30
CVE-2024-7080 SourceCodester Insurance Management System direct request CWE-425 5.3 Medium2024-07-24
CVE-2024-7068 SourceCodester Insurance Management System update_sub_category cross site scripting CWE-79 3.5 Low2024-07-24
CVE-2024-2150 SourceCodester Insurance Management System file inclusion CWE-73 5.3 Medium2024-03-03

All 13 known CVE vulnerabilities affecting Insurance Management System with full Chinese analysis, references, and POCs where available.