Security Advisory

CVE-2020-36034

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-08-11 00:00:00
Last updated 2024-10-09 17:55:36
Assigner mitre
State PUBLISHED

Description

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.