Record summary

CVE-2020-25762 has a selected CVSS score of 9.1 (critical); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSeat Reservation System 1.0 - Unauthenticated SQL InjectionExploitDB exploitby Rahul RamkumarNot analyzed1 file
ExploitDB

PoC details

References

4