Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25763
Reference (s):
- FULLDISC:20200922 Seat Reservation System 1.0 Unauthenticated Remote Code Execution (CVE-2020-25763)
- URL: http://seclists.org/fulldisclosure/2020/Sep/41
- http://packetstormsecurity.com/files/159260/Seat-Reservation-System-1.0-Shell-Upload.html
- https://packetstormsecurity.com/files/author/15149