PT-2017-14879 · Fs · Fs Makemytrip Clone

Ihsan Sencan

+1

·

Published

2017-12-13

·

Updated

2020-09-29

·

CVE-2017-17584

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FS Makemytrip Clone version 1.0
Description The issue is related to SQL Injection, which can be exploited via the "show-flight-result.php" endpoint, specifically through the fl orig or fl dest parameters.
Recommendations For FS Makemytrip Clone version 1.0, consider restricting access to the "show-flight-result.php" endpoint or validating and sanitizing the fl orig and fl dest parameters to prevent SQL Injection attacks. As a temporary workaround, avoid using the fl orig and fl dest parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17584

Affected Products

Fs Makemytrip Clone