Impact
A flaw is present in. The flaw resides in the treatment of the 'tour' argument within the /admin/tour_reserves.php file, allowing a malicious attacker to inject arbitrary SQL statements into an underlying query. This constitutes a classic SQL injection vulnerability (CInstallations of code-projects Hotel and Tourism Reservation 1.0 are vulnerable. No other product versions or vendors are listed as affected based on the current CNA data.
Affected Systems
The affected product is code-projects Hotel and Tourism Reservation version 1.0, specifically the Tour Reservations Page component accessed via /admin/tour_reserves.php. No other product versions or vendors are listed as affected based on CNA data.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as medium severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack code has been published and the flaw can be triggered remotely, implying that a threat actor could craft a request to the vulnerable endpoint from any network location capable of reaching the host. Remote access increases the potential for exploitation under the right circumstances, though the actual exploitation likelihood remains low.
OpenCVE Enrichment