First published: Thu Jan 25 2024(Updated: )
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec of the file payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252035.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mayurik Online Tours & Travels Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0884 is rated as critical due to its potential for remote exploitation through SQL injection.
CVE-2024-0884 impacts the exec function in payment.php, allowing malicious actors to manipulate the id argument.
Yes, CVE-2024-0884 can be exploited remotely, making it a serious concern for users of the affected system.
CVE-2024-0884 affects Mayurik Online Tours & Travels Management System version 1.0.
To fix CVE-2024-0884, it is recommended to sanitize and validate input data, specifically for the exec function in payment.php.