CVE-2020-25990
CRITICALWebsiteBaker 2.12.2 - SQL Injection via Display Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25990. PoCs published by Roel van Beurden.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in WebsiteBaker 2.12.2 via the 'display_name' parameter in /admin/preferences/save.php. It includes a proof-of-concept payload and instructions for using SQLmap to extract database information.
Description
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in WebsiteBaker 2.12.2 via the 'display_name' parameter in /admin/preferences/save.php. It includes a proof-of-concept payload and instructions for using SQLmap to extract database information.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H