PT-2022-20700 · Unknown · Online Car Wash Booking System

K0Xx11

·

Published

2022-06-01

·

Updated

2026-02-18

·

CVE-2022-31344

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Car Wash Booking System version 1.0
Description The issue concerns a SQL Injection vulnerability. It can be exploited via the /ocwbs/classes/Master.php API endpoint, specifically when the f parameter is set to delete booking.
Recommendations For Online Car Wash Booking System version 1.0, consider restricting access to the delete booking function in the Master.php file until a patch is available. Avoid using the f parameter in the /ocwbs/classes/Master.php endpoint with the delete booking value to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31344

Affected Products

Online Car Wash Booking System