CVE-2017-20125: Online Hotel Booking System Pro roomtype-details.php sql injection
Published Jun 30, 2022
·Updated
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
bestsoftinc Online Hotel Booking System=1.2
Event History
Jun 30, 2022
CVE Published
via MITRE·05:05 AM
Data Sourced
via MITRE·05:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-20125?
CVE-2017-20125 is classified as a critical vulnerability.
2
How does CVE-2017-20125 impact the Online Hotel Booking System?
CVE-2017-20125 allows for SQL injection through the manipulation of the tid argument in the file /roomtype-details.php.
3
Can CVE-2017-20125 be exploited remotely?
Yes, CVE-2017-20125 can be exploited remotely by an attacker.
4
How do I fix CVE-2017-20125?
To fix CVE-2017-20125, sanitize user inputs to prevent SQL injection in the affected application.
5
What version of Online Hotel Booking System is affected by CVE-2017-20125?
CVE-2017-20125 affects Online Hotel Booking System Pro version 1.2.