VendorsOnline Bus Booking System Projectonline_bus_booking_system1.0
Vulnerabilities

Online Bus Booking System Project Online Bus Booking System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-25889
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
Published 2020-12-08 · Modified
9.8EPSS 0.028
CVE-2020-25273
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
Published 2020-10-08 · Modified
9.8EPSS 0.018
CVE-2023-45015
Online Bus Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
Published 2023-11-02 · Modified
9.8EPSS 0.007
CVE-2023-45018
Online Bus Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
Published 2023-11-02 · Modified
9.8EPSS 0.007
CVE-2023-45019
Online Bus Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
Published 2023-11-02 · Modified
9.8EPSS 0.007
CVE-2023-45012
Online Bus Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
Published 2023-11-02 · Modified
9.8EPSS 0.007
CVE-2020-25272
In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.
Published 2020-10-08 · Modified
6.1EPSS 0.009