ZeroHour

CVE-2020-36034

PoC
CVSS 3.1
9.8 critical
EPSS
2%p75
Published
()
Modified
Description

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

Vendors
school faculty scheduling system project
Products
school faculty scheduling system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.