An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-09-29T19:11:53
Updated: 2024-08-04T15:40:36.955Z
Reserved: 2020-09-18T00:00:00
Link: CVE-2020-25762
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-30T18:15:25.523
Modified: 2024-11-21T05:18:42.040
Link: CVE-2020-25762
Redhat
No data.