CVE-2020-11545 Information
Feb 14, 2021
cve
Description
Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues as demonstrated by the email and parameters (account.php) uname and pass parameters (login.php) and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://frostylabs.net/writeups/cve-2020-11545/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: