High severity8.8NVD Advisory· Published Sep 30, 2020· Updated Jun 17, 2026
CVE-2020-25760
CVE-2020-25760
Description
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:projectworlds:visitor_management_system:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:projectworlds:visitor_management_system:1.0:*:*:*:*:*:*:*
- (no CPE)range: 1.0
- Projectworlds/Visitor Management System in PHPdescription
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/159262/Visitor-Management-System-In-PHP-1.0-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/159637/Visitor-Management-System-In-PHP-1.0-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2020/Sep/43nvdExploitMailing ListThird Party Advisory
- packetstormsecurity.com/files/author/15149/nvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/48911nvd
News mentions
0No linked articles in our index yet.