CVE-2024-0735: SourceCodester Online Tours & Travels Management System expense.php exec sql injection
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. Affected by this issue is the function exec of the file admin/operations/expense.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251558 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0735?
CVE-2024-0735 has been rated as critical due to its potential for exploitation.
How does CVE-2024-0735 affect the Online Tours & Travels Management System?
CVE-2024-0735 allows for SQL injection through the exec function in the expense.php file.
Who is affected by CVE-2024-0735?
CVE-2024-0735 affects users of SourceCodester Online Tours & Travels Management System version 1.0.
How can I fix CVE-2024-0735?
To fix CVE-2024-0735, it is recommended to sanitize and validate user inputs in the affected PHP file to prevent SQL injection.
Can CVE-2024-0735 be exploited remotely?
Yes, CVE-2024-0735 can be exploited remotely, making it particularly dangerous.