CVE-2020-25760

HIGH

Projectworlds Visitor Management System - SQL Injection

Title source: rule
STIX 2.1

Description

Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.

Exploits (1)

exploitdb WORKING POC
by Rahul Ramkumar · textwebappsphp
https://www.exploit-db.com/exploits/48911

Scores

CVSS v3 8.8
EPSS 0.0037
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
projectworlds/visitor_management_system 1.0
Published Sep 30, 2020
Tracked Since Feb 18, 2026