PT-2017-14879 · Fs · Fs Makemytrip Clone
Ihsan Sencan
+1
·
Published
2017-12-13
·
Updated
2020-09-29
·
CVE-2017-17584
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FS Makemytrip Clone version 1.0
Description
The issue is related to SQL Injection, which can be exploited via the "show-flight-result.php" endpoint, specifically through the
fl orig or fl dest parameters.Recommendations
For FS Makemytrip Clone version 1.0, consider restricting access to the "show-flight-result.php" endpoint or validating and sanitizing the
fl orig and fl dest parameters to prevent SQL Injection attacks. As a temporary workaround, avoid using the fl orig and fl dest parameters in the affected endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fs Makemytrip Clone