CVE-2020-36034
Summary
| CVE | CVE-2020-36034 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-11 14:15:00 UTC |
| Updated | 2023-08-17 01:51:00 UTC |
| Description | SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | School Faculty Scheduling System Project | School Faculty Scheduling System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - TCSWT/School-Faculty-Scheduling-System | MISC | github.com | |
| School Faculty Scheduling System using PHP/MySQLi with Source Code | Free Source Code & Tutorials | MISC | www.sourcecodester.com | |
| Downloading School Faculty Scheduling System using PHP/MySQLi with Source Code Code | SourceCodester | MISC | www.sourcecodester.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.