CVE-2024-10411: SourceCodester Online Hotel Reservation System controller.php doCheckout sql injection
A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file /marimar/admin/modroom/controller.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10411?
CVE-2024-10411 has been classified as a critical vulnerability.
How do I fix CVE-2024-10411?
To fix CVE-2024-10411, you should update the SourceCodester Online Hotel Reservation System to the latest version.
What components are affected by CVE-2024-10411?
CVE-2024-10411 affects the functions doCancelRoom, doCancel, doConfirm, doCheckin, and doCheckout in the controller.php file.
What type of attack can exploit CVE-2024-10411?
CVE-2024-10411 can be exploited through unauthorized manipulation of the aforementioned functions.
Is CVE-2024-10411 specific to a software version?
Yes, CVE-2024-10411 specifically affects version 1.0 of the Janobe Online Hotel Reservation System.