CVE-2020-11545

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
06/04/2020
Last modified:
06/04/2020

Description

Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:projectworlds:official_car_rental_system:1.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools