itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.
History

Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Online Tours And Travels Management System Project
Online Tours And Travels Management System Project online Tours And Travels Management System
Weaknesses CWE-89
CPEs cpe:2.3:a:online_tours_and_travels_management_system_project:online_tours_and_travels_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Online Tours And Travels Management System Project
Online Tours And Travels Management System Project online Tours And Travels Management System
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 21:00:00 +0000

Type Values Removed Values Added
Description itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-15T00:00:00

Updated: 2024-10-16T18:18:10.087Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48411

cve-icon Vulnrichment

Updated: 2024-10-16T18:18:03.657Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-15T21:15:11.060

Modified: 2024-10-16T19:35:11.290

Link: CVE-2024-48411

cve-icon Redhat

No data.