CVE-2024-3348: SourceCodester Aplaya Beach Resort Online Reservation System index.php sql injection
A vulnerability classified as critical has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected is an unknown function of the file booking/index.php. The manipulation of the argument logemail/logpword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259452.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3348?
CVE-2024-3348 is classified as a critical vulnerability.
How does CVE-2024-3348 affect the Aplaya Beach Resort Online Reservation System?
CVE-2024-3348 allows for SQL injection through the manipulation of the log_email and log_pword arguments.
What software versions are affected by CVE-2024-3348?
CVE-2024-3348 affects version 1.0 of the SourceCodester Aplaya Beach Resort Online Reservation System.
How do I fix CVE-2024-3348?
To fix CVE-2024-3348, validate and sanitize user inputs to prevent SQL injection.
What is the potential impact of exploiting CVE-2024-3348?
Exploiting CVE-2024-3348 can lead to unauthorized access to sensitive data in the database.