CVE-2020-25762
Last modified
CVE-2020-25762 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. EPSS estimates a 11.30% chance of exploitation in the next 30 days.
Description
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Seat Reservation System Project | Seat Reservation System | 1.0 |
References
- http://packetstormsecurity.com/files/159261/Seat-Reservation-System-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/42Exploit, Mailing List, Third Party Advisory
- https://packetstormsecurity.com/files/author/15149Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/159261/Seat-Reservation-System-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/42Exploit, Mailing List, Third Party Advisory
- https://packetstormsecurity.com/files/author/15149Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25762?
How severe is CVE-2020-25762?
How do I fix CVE-2020-25762?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-25757A lack of input validation and access controls in Lua CGIs o…8.8
- CVE-2020-25758An issue was discovered on D-Link DSR-250 3.17 devices. Insu…8.8
- CVE-2020-25759An issue was discovered on D-Link DSR-250 3.17 devices. Cert…8.8
- CVE-2020-2576Vulnerability in the Oracle Outside In Technology product of…6.5
- CVE-2020-25760Projectworlds Visitor Management System in PHP 1.0 allows SQ…8.8
- CVE-2020-25761Projectworlds Visitor Management System in PHP 1.0 allows XS…6.1
- CVE-2020-25763Seat Reservation System version 1.0 suffers from an Unauthen…9.8
- CVE-2020-25765Addressed remote code execution vulnerability in reg_device.…9.8
- CVE-2020-25766An issue was discovered in MISP before 2.4.132. It can perfo…7.5
- CVE-2020-25767An issue was discovered in HCC Embedded NicheStack IPv4 4.1.…7.5
- CVE-2020-25768Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before …5.3
- CVE-2020-2577Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
Are you affected by CVE-2020-25762?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
