CVE-2020-29214
CRITICALNuclei
Alumni Management System 1.0 - Authentication Bypass
Record summary
CVE-2020-29214 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBAlumni Management System 1.0 - Authentication BypassExploitDB exploitby Ankita PalNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALAlumni Management System 1.0 - SQL InjectionCVSS 9.8
SourceCodester Alumni Management System 1.0 contains a sql_injection caused by unsanitized input in admin/login.php, letting attackers bypass authentication, exploit requires injection of malicious SQL payload.
Impact
Unauthenticated attackers can bypass authentication through SQL injection, gaining administrative access to the Alumni Management System and access to all alumni data.
Remediation
Apply vendor patches or upgrade to a patched version.
WeaknessesCWE-89
Authorsarafatansari
Template tagscvecve2020sqliauth-bypasscmsedbalumnivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:alumni_management_system_project:alumni_management_system:1.0:*:*:*:*:*:*:*
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-29214 48883exploit
https://www.exploit-db.com/exploits/48883