CVE detail
CVE-2020-25762 — CVE-2020-25762
Published 2020-09-30 · Modified 2026-06-17 · Vendor seat_reservation_system_project · Product seat_reservation_system · Source nvd
CRITICAL
severity
CVSS-derived band
0.1130
EPSS probability
exploitation probability, 30d
96.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References