VulnerabilityModified
CVE-2020-25760
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection.
HIGH 8.8EPSS 2.17%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.17% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- projectworlds/visitor management system
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/159262/Visitor-Management-System-In-PHP-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/159637/Visitor-Management-System-In-PHP-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/43Exploit, Mailing List, Third Party Advisory
- https://packetstormsecurity.com/files/author/15149/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/48911
- http://packetstormsecurity.com/files/159262/Visitor-Management-System-In-PHP-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/159637/Visitor-Management-System-In-PHP-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/43Exploit, Mailing List, Third Party Advisory
- https://packetstormsecurity.com/files/author/15149/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.