Vulnerability Description
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Online Bus Booking System Project | Online Bus Booking System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/Ko-kn3t/CVE-2020-25273ExploitThird Party Advisory
- https://www.sourcecodester.comThird Party Advisory
- https://github.com/Ko-kn3t/CVE-2020-25273ExploitThird Party Advisory
- https://www.sourcecodester.comThird Party Advisory
FAQ
What is CVE-2020-25273?
CVE-2020-25273 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
How severe is CVE-2020-25273?
CVE-2020-25273 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-25273?
Check the references section above for vendor advisories and patch information. Affected products include: Online Bus Booking System Project Online Bus Booking System.