ZeroHour

CVE-2020-25889

PoC
CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.

Vendors
online bus booking system project
Products
online bus booking system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.