packetstormsecurity.com
http://packetstormsecurity.com/files/159261/Seat-Reservation-System-1.0-SQL-Injection.html CVE-2020-25762
CRITICAL
Seat Reservation System 1.0 - Unauthenticated SQL Injection
Record summary
CVE-2020-25762 has a selected CVSS score of 9.1 (critical); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSeat Reservation System 1.0 - Unauthenticated SQL InjectionExploitDB exploitby Rahul RamkumarNot analyzed1 file
References
420200922 Seat Reservation System 1.0 Unauthenticated SQL Injection (CVE-2020-25762)mailing list
http://seclists.org/fulldisclosure/2020/Sep/42 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-25762 packetstormsecurity.com
https://packetstormsecurity.com/files/author/15149