CVE-2020-28183

CRITICAL

SourceCodester Water Billing System 1.0 - SQL Injection via Username and Password Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-28183. PoCs published by Sarang Tumne.

AI-analyzed exploit summary This exploit demonstrates SQL injection in the 'username' and 'password' parameters of Water Billing System 1.0. It bypasses authentication by injecting SQL conditions, allowing unauthorized access to the application.

Description

SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.

Exploits (1)

exploitdb WORKING POC
by Sarang Tumne · textwebappsphp
https://www.exploit-db.com/exploits/49032

This exploit demonstrates SQL injection in the 'username' and 'password' parameters of Water Billing System 1.0. It bypasses authentication by injecting SQL conditions, allowing unauthorized access to the application.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Water Billing System 1.0
No auth needed
Prerequisites: Access to the login page of the Water Billing System
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0253
EPSS Percentile 82.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
water_billing_system_project/water_billing_system 1.0
Published Nov 17, 2020
Tracked Since Feb 18, 2026