{"api_version":"1","generated_at":"2026-07-23T10:32:10+00:00","cve":"CVE-2020-36034","urls":{"html":"https://cve.report/CVE-2020-36034","api":"https://cve.report/api/cve/CVE-2020-36034.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-36034","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-36034"},"summary":{"title":"CVE-2020-36034","description":"SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-08-11 14:15:00","updated_at":"2023-08-17 01:51:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://github.com/TCSWT/School-Faculty-Scheduling-System","name":"https://github.com/TCSWT/School-Faculty-Scheduling-System","refsource":"MISC","tags":[],"title":"GitHub - TCSWT/School-Faculty-Scheduling-System","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.sourcecodester.com/php/14535/school-faculty-scheduling-system-using-phpmysqli-source-code.html","name":"https://www.sourcecodester.com/php/14535/school-faculty-scheduling-system-using-phpmysqli-source-code.html","refsource":"MISC","tags":[],"title":"School Faculty Scheduling System using PHP/MySQLi with Source Code | Free Source Code & Tutorials","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.sourcecodester.com/download-code?nid=14535&title=School+Faculty+Scheduling+System+using+PHP%2FMySQLi+with+Source+Code","name":"https://www.sourcecodester.com/download-code?nid=14535&title=School+Faculty+Scheduling+System+using+PHP%2FMySQLi+with+Source+Code","refsource":"MISC","tags":[],"title":"Downloading School Faculty Scheduling System using PHP/MySQLi with Source Code Code | SourceCodester","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-36034","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-36034","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"36034","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"school_faculty_scheduling_system_project","cpe5":"school_faculty_scheduling_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-36034","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.sourcecodester.com/php/14535/school-faculty-scheduling-system-using-phpmysqli-source-code.html","refsource":"MISC","name":"https://www.sourcecodester.com/php/14535/school-faculty-scheduling-system-using-phpmysqli-source-code.html"},{"url":"https://github.com/TCSWT/School-Faculty-Scheduling-System","refsource":"MISC","name":"https://github.com/TCSWT/School-Faculty-Scheduling-System"},{"url":"https://www.sourcecodester.com/download-code?nid=14535&title=School+Faculty+Scheduling+System+using+PHP%2FMySQLi+with+Source+Code","refsource":"MISC","name":"https://www.sourcecodester.com/download-code?nid=14535&title=School+Faculty+Scheduling+System+using+PHP%2FMySQLi+with+Source+Code"}]}},"nvd":{"publishedDate":"2023-08-11 14:15:00","lastModifiedDate":"2023-08-17 01:51:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:school_faculty_scheduling_system_project:school_faculty_scheduling_system:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"36034","Ordinal":"196059","Title":"CVE-2020-36034","CVE":"CVE-2020-36034","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"36034","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}