PT-2026-21449 · Unknown · Web Ofisi Rent A Car Version 3
Published
2026-02-22
·
Updated
2026-02-22
·
CVE-2019-25462
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Web Ofisi Rent a Car version 3
Description
The software contains an SQL injection flaw. Unauthenticated attackers can manipulate database queries by injecting SQL code through the
klima parameter. Attackers can send GET requests with malicious klima values to extract sensitive database information or cause a denial of service. The vulnerable API endpoint is not specified.Recommendations
Apply any available updates to address the issue. As a temporary workaround, sanitize or validate the
klima parameter to prevent SQL injection attacks.Exploit
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web Ofisi Rent A Car Version 3