First published: Thu Jun 30 2022(Updated: )
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Online Hotel Booking System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-20124 is classified as a critical vulnerability.
To fix CVE-2017-20124, update the Online Hotel Booking System Pro Plugin to a version that mitigates the SQL injection vulnerability.
CVE-2017-20124 is associated with a SQL injection attack that can be performed remotely.
The vulnerability affects the function located in the file /front/roomtype-details.php of the Online Hotel Booking System Pro Plugin.
The potential risks include unauthorized database access, data manipulation, and compromise of the website's integrity.