CVE-2020-25889
08.12.2020, 13:15
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
| Vendor | Product | Version |
|---|---|---|
| online_bus_booking_system_project | online_bus_booking_system | 1.0 |
𝑥
= Vulnerable software versions
References