CRITICAL
Online Bus Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
Published Nov 2, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.70%
Description
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received and they are sent unfiltered to the database.
Affected products
-
Affected
- 1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Projectworlds Pvt. Limited | Online Bus Booking System | unaffected | Affected
|
- 1.0
-
Affected
- 1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Online Bus Booking System Project | Online Bus Booking System | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-49341 Advisory
- https://fluidattacks.com/advisories/oconnor third-party-advisoryExploitThird Party Advisory
- https://projectworlds.in/ Product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-49341 | Advisory | |
| https://fluidattacks.com/advisories/oconnor | third-party-advisoryExploitThird Party Advisory | |
| https://projectworlds.in/ | Product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Nov 2, 2023
Updated Sep 5, 2024
Reserved Oct 2, 2023
Link CVE-2023-45019
CISA Vulnrichment
Updated Sep 5, 2024
Red Hat
No data
GitHub
No data