CVE-2020-24932

CRITICAL

Sourcecodester Complaint Management System 1.0 - SQL Injection via cid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-24932. PoCs published by Mohamed Elobeid.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Complaint Management System 1.0 via the 'cid' parameter. It uses sqlmap to automate the exploitation process for retrieving database information.

Description

An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

Exploits (1)

exploitdb SCANNER
by Mohamed Elobeid · textwebappsphp
https://www.exploit-db.com/exploits/48758

This exploit demonstrates an SQL injection vulnerability in Complaint Management System 1.0 via the 'cid' parameter. It uses sqlmap to automate the exploitation process for retrieving database information.

Classification
Scanner 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Complaint Management System 1.0
Auth required
Prerequisites: Access to the admin panel · Valid PHPSESSID cookie
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/48758

Scores

CVSS v3 9.8
EPSS 0.0159
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
razormist/complaint_management_system 1.0
sourcecodester/complaint_management_system 1.0
Published Oct 27, 2021
Tracked Since Feb 18, 2026