PT-2017-14915 · Unknown · Laundry Booking Script

Ihsan Sencan

·

Published

2017-12-13

·

Updated

2017-12-26

·

CVE-2017-17619

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Laundry Booking Script version 1.0
Description The issue is related to SQL Injection, which can be exploited via the city parameter in the "/list" API endpoint.
Recommendations For Laundry Booking Script version 1.0, consider restricting access to the "/list" API endpoint or disabling the city parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17619

Affected Products

Laundry Booking Script