Vulnerability Description
Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Seat Reservation System Project | Seat Reservation System | 1.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/159260/Seat-Reservation-System-1.0-Shell-UpExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/41ExploitMailing ListThird Party Advisory
- https://packetstormsecurity.com/files/author/15149Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/159260/Seat-Reservation-System-1.0-Shell-UpExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/41ExploitMailing ListThird Party Advisory
- https://packetstormsecurity.com/files/author/15149Third Party AdvisoryVDB Entry
FAQ
What is CVE-2020-25763?
CVE-2020-25763 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP f...
How severe is CVE-2020-25763?
CVE-2020-25763 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-25763?
Check the references section above for vendor advisories and patch information. Affected products include: Seat Reservation System Project Seat Reservation System.