Vulnerabilities (CVE)

Filtered by CWE-89
Total 15161 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25889 1 Online Bus Booking System Project 1 Online Bus Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
CVE-2020-25839 1 Microfocus 1 Identity Manager 2024-11-21 7.5 HIGH 9.8 CRITICAL
NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.
CVE-2020-25762 1 Seat Reservation System Project 1 Seat Reservation System 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
CVE-2020-25760 1 Projectworlds 1 Visitor Management System In Php 2024-11-21 6.5 MEDIUM 8.8 HIGH
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
CVE-2020-25751 1 Corephp 1 Pago Commerce 2024-11-21 6.5 MEDIUM 8.8 HIGH
The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.
CVE-2020-25727 1 Flexsolution 1 Reset Password 2024-11-21 5.0 MEDIUM 7.5 HIGH
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.
CVE-2020-25700 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.
CVE-2020-25695 2 Debian, Postgresql 2 Debian Linux, Postgresql 2024-11-21 6.5 MEDIUM 8.8 HIGH
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2020-25608 1 Mitel 1 Micollab 2024-11-21 6.5 MEDIUM 7.2 HIGH
The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.
CVE-2020-25514 1 Simple Library Management System Project 1 Simple Library Management System 2024-11-21 4.6 MEDIUM 8.4 HIGH
Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php.
CVE-2020-25487 1 Phpgurukul 1 Zoo Management System 2024-11-21 4.6 MEDIUM 7.8 HIGH
PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.
CVE-2020-25475 1 Newsscriptphp 1 News Script Php Pro 2024-11-21 7.5 HIGH 9.8 CRITICAL
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
CVE-2020-25409 1 College Management System Project 1 College Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
CVE-2020-25379 1 Recall-products Project 1 Recall-products 2024-11-21 6.5 MEDIUM 8.8 HIGH
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.
CVE-2020-25362 1 Online Shopping Alphaware Project 1 Online Shopping Alphaware 2024-11-21 5.0 MEDIUM 7.5 HIGH
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
CVE-2020-25273 1 Online Bus Booking System Project 1 Online Bus Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
CVE-2020-25254 1 Hyland 1 Onbase 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by TestConnection_LocalOrLinkedServer, CreateFilterFriendlyView, or AddWorkViewLinkedServer.
CVE-2020-25253 1 Hyland 1 Onbase 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by the TableName, ColumnName, Name, UserId, or Password parameter.
CVE-2020-25157 1 Advantech 1 R-seenet 2024-11-21 5.0 MEDIUM 7.5 HIGH
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
CVE-2020-25147 1 Observium 1 Observium 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. This can occur via username[0] to the default URI, because of includes/authenticate.inc.php.