ZeroHour

CVE-2020-25760

PoC ×4
CVSS 3.1
8.8 high
EPSS
2%p81
Published
()
Modified
Description

Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.

Vendors
projectworlds
Products
visitor management system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.