Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2024-01-04T14:31:24.671Z

Updated: 2024-08-02T22:23:43.607Z

Reserved: 2023-12-14T17:47:18.224Z

Link: CVE-2023-50864

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-04T15:15:10.003

Modified: 2024-01-10T01:12:35.763

Link: CVE-2023-50864

cve-icon Redhat

No data.