Lucene search

K
cvelistMitreCVELIST:CVE-2020-35674
HistoryDec 24, 2020 - 3:05 a.m.

CVE-2020-35674

2020-12-2403:05:28
mitre
www.cve.org
1

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.7%

BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a request containing a crafted payload that can result in sensitive information being extracted from the database, eventually leading into an application takeover. This vulnerability was introduced as a result of the developer trying to roll their own sanitization implementation in order to allow the application to be used in legacy environments.

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.7%

Related for CVELIST:CVE-2020-35674