SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.
History

Wed, 09 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-08-11T00:00:00

Updated: 2024-10-09T17:55:36.740Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2020-36034

cve-icon Vulnrichment

Updated: 2024-08-04T17:16:14.109Z

cve-icon NVD

Status : Analyzed

Published: 2023-08-11T14:15:11.643

Modified: 2023-08-17T01:51:43.793

Link: CVE-2020-36034

cve-icon Redhat

No data.