PT-2022-18812 · Unknown · Online Sports Complex Booking System

Published

2022-05-20

·

Updated

2022-05-26

·

CVE-2022-28105

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Sports Complex Booking System version 1.0
Description The issue is related to a blind SQL injection vulnerability. This vulnerability can be exploited via the id parameter in the "/scbs/view facility.php" API endpoint.
Recommendations For Online Sports Complex Booking System version 1.0, avoid using the id parameter in the "/scbs/view facility.php" endpoint until a fix is available. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28105

Affected Products

Online Sports Complex Booking System