CVE-2020-25362

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
02/06/2021
Last modified:
09/06/2021

Description

The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:online_shopping_alphaware_project:online_shopping_alphaware:1.0:*:*:*:*:*:*:*