Vulnerability Database
Blog
FAQ
Docs
CVE-2020-13433
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2020-13433
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13433.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13433
Published
2020-05-24T22:15:10Z
Modified
2025-01-14T08:19:45.712689Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
References
https://github.com/Jason2605/AdminPanel/pull/41
https://news.websec.nl/news-cve-report-0.html
Affected packages
Git
/
github.com/jason2605/adminpanel
Affected ranges
Type
GIT
Repo
https://github.com/jason2605/adminpanel
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
1ae8f07860fe4fc07853b930adce25d452636571
Affected versions
1.*
1.6
1.6.1
1.6.1.1
1.6.2
1.6.2.1
1.6.2.2
1.6.3
2.*
2.0
2.0.0.0.1
2.5.0
2.5.0.0.0.1
2.5.5
2.5.5.1
2.5.6
2.5.6.0.0.0.1
2.7
2.8
2.8.5
3.*
3.0.0
3.5.0
3.5.0.1
3.5.5
3.5.5.6
4.*
4.0
v1.*
v1.0
v1.5
CVE-2020-13433 - OSV