PT-2020-17135 · Unknown · Car Rental Management System

Bigtiger2020

·

Published

2020-12-02

·

Updated

2020-12-03

·

CVE-2020-29287

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Car Rental Management System version 1.0
Description An SQL injection issue was found in the Car Rental Management System. This can be exploited through the id parameter in "view car.php" or the car id parameter in "booking.php".
Recommendations For Car Rental Management System version 1.0, consider restricting access to the "view car.php" and "booking.php" files until a patch is available. As a temporary workaround, avoid using the id and car id parameters in the affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29287

Affected Products

Car Rental Management System