SQL Injection Vulnerability in oretnom23 School Faculty Scheduling System v1.0: Remote Code Execution, Privilege Escalation, and Information Disclosure

SQL Injection Vulnerability in oretnom23 School Faculty Scheduling System v1.0: Remote Code Execution, Privilege Escalation, and Information Disclosure

CVE-2020-36034 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

Learn more about our User Device Pen Test.