PT-2022-19757 · Unknown · Online Sports Complex Booking System

Published

2022-05-19

·

Updated

2023-08-08

·

CVE-2022-29652

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Online Sports Complex Booking System version 1.0
Description The issue concerns SQL Injection via the "/scbs/classes/Users.php?f=save client" endpoint. This allows for potential manipulation of database queries, which could lead to unauthorized access or data modification.
Recommendations For Online Sports Complex Booking System version 1.0, consider disabling the save client function in the Users.php file as a temporary workaround until a patch is available. Restrict access to the "/scbs/classes/Users.php?f=save client" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-29652

Affected Products

Online Sports Complex Booking System