PT-2026-5831 · Fishing Reservation System · Fishing Reservation System

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2020-37081

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fishing Reservation System version 7.5
Description Remote SQL injection issues exist in the 'admin.php', 'cart.php', and 'calendar.php' endpoints. Attackers can inject malicious SQL commands through the uid, pid, type, m, y, and code parameters to compromise the database management system and the web application without user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-37081

Affected Products

Fishing Reservation System