PT-2026-21449 · Unknown · Web Ofisi Rent A Car Version 3
Publicado
2026-02-22
·
Atualizado
2026-02-22
·
CVE-2019-25462
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Web Ofisi Rent a Car version 3
Description
The software contains an SQL injection flaw. Unauthenticated attackers can manipulate database queries by injecting SQL code through the
klima parameter. Attackers can send GET requests with malicious klima values to extract sensitive database information or cause a denial of service. The vulnerable API endpoint is not specified.Recommendations
Apply any available updates to address the issue. As a temporary workaround, sanitize or validate the
klima parameter to prevent SQL injection attacks.Exploit
Correção
DoS
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Web Ofisi Rent A Car Version 3