← Back to CVE List

CVE-2020-25762

Published: 2020-09-30T18:15Z
Last Modified: 2024-11-21T05:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt