Seat Reservation System ProjectCVEs & Vulnerabilities
2 CVEs affecting Seat Reservation System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
seat reservation system 2
CVE-2020-25763CRITICAL
Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
30 Sep 2020
9.8
CVSS
CVE-2020-25762CRITICALpoc
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
30 Sep 2020
9.1
CVSS
← PrevPage 1 / 1Next →