CVE-2020-25760
HIGHProjectworlds Visitor Management System - SQL Injection
Title source: ruleDescription
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
Exploits (1)
References (5)
Scores
CVSS v3
8.8
EPSS
0.0037
EPSS Percentile
58.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
projectworlds/visitor_management_system
1.0
Published
Sep 30, 2020
Tracked Since
Feb 18, 2026