PT-2024-30011 · Unknown · Hotel Management System

Topsky979

·

Published

2024-08-20

·

Updated

2024-08-23

·

CVE-2024-42552

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Hotel Management System version 91caab8
Description A SQL injection vulnerability was discovered in the Hotel Management System via the book id parameter at the "admin room history.php" endpoint. This issue allows for potential unauthenticated remote exploitation. Administrators should review logs for signs of compromise.
Recommendations For Hotel Management System version 91caab8, consider disabling access to the "admin room history.php" endpoint until a patch is available. Restrict the use of the book id parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-42552

Affected Products

Hotel Management System