PT-2024-33053 · Unknown · Vehicle Management System
Shadowbyte1
·
Published
2024-12-23
·
Updated
2025-01-08
·
CVE-2024-48245
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vehicle Management System versions 1.0 through 1.3
Description
The issue concerns a SQL injection vulnerability. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include
Booking ID, Action Name, and Payment Confirmation ID, which are present in "/newvehicle.php" and "/newdriver.php".Recommendations
For Vehicle Management System versions 1.0 through 1.3, consider disabling the vulnerable parameters
Booking ID, Action Name, and Payment Confirmation ID in the affected API endpoints "/newvehicle.php" and "/newdriver.php" until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation. Avoid using the vulnerable parameters in administrative actions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vehicle Management System