vendor:
Aplaya Beach Resort Online Reservation System
by:
Ihsan Sencan
8.8
CVSS
HIGH
Multiple Vulnerabilities
89, 264, 79
CWE
Product Name: Aplaya Beach Resort Online Reservation System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:sourcecodester:aplaya_beach_resort_online_reservation_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
Aplaya Beach Resort Online Reservation System 1.0 – Multiple Vulnerabilities
Aplaya Beach Resort Online Reservation System 1.0 is vulnerable to multiple attacks. The first vulnerability is an SQL injection vulnerability which allows an attacker to inject malicious SQL queries into the application. The second vulnerability is a file upload vulnerability which allows an attacker to upload malicious files to the application. The third vulnerability is a cross-site scripting vulnerability which allows an attacker to inject malicious JavaScript code into the application.
Mitigation:
The application should be patched to prevent SQL injection, file upload and cross-site scripting attacks. Input validation should be implemented to prevent malicious input from being accepted. The application should also be configured to only accept files of a certain type and size.