Vendor Homepageproduct
https://github.com/amitkolloldey/elearning-script CVE-2020-37035
HIGH
e-learning Php Script 0.1.0 - 'search' SQL Injection
Record summary
CVE-2020-37035 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 2, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
e-learning PHP ScriptBrowse amitkolloldey / e-learning PHP Script | CVE List | 0.1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBe-learning Php Script 0.1.0 - 'search' SQL InjectionExploitDB exploitby KeopssGroup0day_IncNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37035 ExploitDB-48629exploit
https://www.exploit-db.com/exploits/48629 VulnCheck Advisory: e-learning Php Script 0.1.0 - 'search' SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/e-learning-php-script-search-sql-injection