PT-2021-23368 · Unknown · Hotel-Mgmt-System

Jason Colyvas

·

Published

2021-10-04

·

Updated

2021-10-12

·

CVE-2021-41651

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Raymart DG / Ahmed Helal Hotel-mgmt-system (affected versions not specified)
Description A blind SQL injection issue exists, allowing a malicious attacker to retrieve sensitive database information and interact with the database. This is achieved through the vulnerable cid parameter in the process update profile.php file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41651

Affected Products

Hotel-Mgmt-System