CVE-2023-0324
high · 7.3A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218426 is the identifier assigned to this vulnerability.
7.3
CVSS
18.8%
EPSS (exploit prob.)
97th
EPSS percentile
2023-01-16
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| online_tours_&_travels_management_system_project | online_tours_&_travels_management_system | 1.0 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/linmoren/online-tours-travels-management-system/blob/main/adminpage-login-email.md
- https://vuldb.com/?ctiid.218426
- https://vuldb.com/?id.218426
- https://github.com/linmoren/online-tours-travels-management-system/blob/main/adminpage-login-email.md
- https://vuldb.com/?ctiid.218426
- https://vuldb.com/?id.218426
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-0324