CVE-2024-0884: SourceCodester Online Tours & Travels Management System payment.php exec sql injection
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec of the file payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252035.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0884?
CVE-2024-0884 is rated as critical due to its potential for remote exploitation through SQL injection.
How does CVE-2024-0884 affect the online tours and travels management system?
CVE-2024-0884 impacts the exec function in payment.php, allowing malicious actors to manipulate the id argument.
Can CVE-2024-0884 be exploited remotely?
Yes, CVE-2024-0884 can be exploited remotely, making it a serious concern for users of the affected system.
What version of the software is affected by CVE-2024-0884?
CVE-2024-0884 affects Mayurik Online Tours & Travels Management System version 1.0.
How do I fix CVE-2024-0884?
To fix CVE-2024-0884, it is recommended to sanitize and validate input data, specifically for the exec function in payment.php.