CVE-2024-6308: itsourcecode Simple Online Hotel Reservation System index.php sql injection
A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269620.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6308?
CVE-2024-6308 has been declared as a critical severity vulnerability.
What component is affected by CVE-2024-6308?
CVE-2024-6308 affects the index.php file in Simple Online Hotel Reservation System version 1.0.
What type of vulnerability is CVE-2024-6308?
CVE-2024-6308 is a SQL injection vulnerability that can be exploited by manipulating the username argument.
How do I fix CVE-2024-6308?
To fix CVE-2024-6308, you should sanitize and validate user inputs, particularly the username argument in index.php.
Can CVE-2024-6308 be exploited remotely?
Yes, CVE-2024-6308 can be exploited remotely by an attacker.