PT-2024-30011 · Unknown · Hotel Management System
Topsky979
·
Published
2024-08-20
·
Updated
2024-08-23
·
CVE-2024-42552
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Hotel Management System version 91caab8
Description
A SQL injection vulnerability was discovered in the Hotel Management System via the
book id parameter at the "admin room history.php" endpoint. This issue allows for potential unauthenticated remote exploitation. Administrators should review logs for signs of compromise.Recommendations
For Hotel Management System version 91caab8, consider disabling access to the "admin room history.php" endpoint until a patch is available. Restrict the use of the
book id parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotel Management System