PT-2021-16461 · Sourcecodester · Sourcecodester Travel Management System

Published

2021-07-22

·

Updated

2021-07-29

·

CVE-2021-25213

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester Travel Management System version 1.0
Description: The issue allows remote attackers to execute arbitrary SQL statements via the catid parameter to "subcat.php" API endpoint. This enables attackers to manipulate database queries, potentially leading to unauthorized data access or modification.
Recommendations: For SourceCodester Travel Management System version 1.0, consider restricting access to the "subcat.php" API endpoint or validating and sanitizing the catid parameter to prevent SQL injection attacks. As a temporary workaround, avoid using the catid parameter in the affected API endpoint until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25213

Affected Products

Sourcecodester Travel Management System