CVE-2020-25273
CRITICALOnline Bus Booking System - SQL Injection
Title source: ruleDescription
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0107
EPSS Percentile
77.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
online_bus_booking_system_project/online_bus_booking_system
1.0
Published
Oct 08, 2020
Tracked Since
Feb 18, 2026