CVE-2020-28172
9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.99% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-03-31 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| simple college project | simple college |
References
- https://dl.packetstormsecurity.net/2010-exploits/simplecollegewebsite10-sqlexec.txt
- https://github.com/yunaranyancat/poc-dump/blob/main/simplecollegewebsite/sqli_rce.py
- https://www.sourcecodester.com/php/14548/simple-college-website-using-htmlphpmysqli-source-code.html
- https://www.sourcecodester.com/sites/default/files/download/oretnom23/simple-college-website.zip
- https://dl.packetstormsecurity.net/2010-exploits/simplecollegewebsite10-sqlexec.txt
- https://github.com/yunaranyancat/poc-dump/blob/main/simplecollegewebsite/sqli_rce.py
- https://www.sourcecodester.com/php/14548/simple-college-website-using-htmlphpmysqli-source-code.html
- https://www.sourcecodester.com/sites/default/files/download/oretnom23/simple-college-website.zip
→ the Explorer · watch your stack · NVD