PT-2024-38543 · Exnet Informatics · Ferry Reservation System
Yağız Bi̇lgi̇li̇
·
Published
2024-09-23
·
Updated
2024-09-26
·
CVE-2024-7735
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Exnet Informatics Software Ferry Reservation System versions prior to 240805-002
Description
The issue is related to an SQL Injection vulnerability due to improper neutralization of special elements used in an SQL command. This allows for SQL Injection, potentially enabling attackers to manipulate data. The vulnerability affects the Ferry Reservation System by Exnet Informatics.
Recommendations
For versions prior to 240805-002, upgrade to a version that includes the fix for this issue to mitigate the risk of remote exploitation and protect sensitive data. As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ferry Reservation System