CVE-2024-0883: SourceCodester Online Tours & Travels Management System pay.php prepare sql injection
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare of the file admin/pay.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252034 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0883?
CVE-2024-0883 is declared as critical due to its potential for SQL injection.
How does CVE-2024-0883 affect the Online Tours & Travels Management System?
CVE-2024-0883 affects the function prepare in the admin/pay.php file, allowing for SQL injection attacks.
What type of vulnerability is CVE-2024-0883?
CVE-2024-0883 is classified as an SQL injection vulnerability.
How can I prevent exploitation of CVE-2024-0883?
To prevent exploitation of CVE-2024-0883, validate and sanitize user input in the affected function.
Is there a patch available for CVE-2024-0883?
As of now, there are no publicly available patches for CVE-2024-0883, so it is crucial to implement mitigation strategies.