Car Rental Management System 1.0 allows an unauthenticated user to perform a file inclusion attack against the /index.php file with a partial filename in the “page” parameter, leading to code execution.
View the template here CVE-2020-29227.yaml
References:
https://github.com/ARPSyndicate/cvemon