CVEs Blog | G5 Cyber Security

CVE-2020-25762 – An issue was discovered in SourceCodester Seat Reservation System 1.0. Th

An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25762

Reference (s):

Exit mobile version