9.8
CVSS
CVE-2020-23833
RCE
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.
Severity: CRITICAL