Lucene search

K
cvelistMitreCVELIST:CVE-2020-25760
HistorySep 29, 2020 - 7:00 p.m.

CVE-2020-25760

2020-09-2919:00:10
mitre
www.cve.org
5
projectworlds
visitor management
sql injection
php
input validation
security vulnerability
database

AI Score

8.8

Confidence

High

EPSS

0.013

Percentile

86.3%

Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the ‘rid’ parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.

AI Score

8.8

Confidence

High

EPSS

0.013

Percentile

86.3%

Related for CVELIST:CVE-2020-25760