CVE-2020-23833: SQL Injection
Published Sep 15, 2020
·Updated
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.
Affected Software
1 affected component
Projectworlds House Rental=1.0
Event History
Sep 15, 2020
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23833?
The severity of CVE-2020-23833 is critical with a severity value of 9.8.
2
How does CVE-2020-23833 affect Projectworlds House Rental v1.0?
CVE-2020-23833 affects Projectworlds House Rental v1.0 by exposing an unauthenticated SQL Injection vulnerability.
3
How can remote attackers exploit CVE-2020-23833?
Remote attackers can exploit CVE-2020-23833 by sending malicious index.php POST requests, allowing them to execute arbitrary code on the hosting webserver.
4
Is there a fix available for CVE-2020-23833?
Currently, there is no known fix available for CVE-2020-23833.
5
What is the Common Weakness Enumeration (CWE) for CVE-2020-23833?
The Common Weakness Enumeration (CWE) for CVE-2020-23833 is CWE-89, which is a vulnerability related to SQL Injection.