CVE-2023-48689
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: help@fluidattacks.com (Secondary)
Description
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfiltered to the database.
Affected (1)
Products: Projectworlds: Railway Reservation System
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
References (4)
Source: help@fluidattacks.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.