Critical severity9.1NVD Advisory· Published Sep 30, 2020· Updated Jun 17, 2026
CVE-2020-25762
CVE-2020-25762
Description
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:seat_reservation_system_project:seat_reservation_system:1.0:*:*:*:*:*:*:*
- SourceCodester/Seat Reservation Systemdescription
- Range: = 1.0
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/159261/Seat-Reservation-System-1.0-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2020/Sep/42nvdExploitMailing ListThird Party Advisory
- packetstormsecurity.com/files/author/15149nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.