Record summary

CVE-2020-10218 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSentrifugo HRMS 3.2 - 'id' SQL InjectionExploitDB exploitby minhnbNot analyzed1 file
ExploitDB

PoC details

References

3