vendor:
Shuttle-Booking-Software
by:
nu11secur1ty
8.1
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Shuttle-Booking-Software
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2023
Shuttle-Booking-Software v1.0 – Multiple-SQLi
The location_id parameter in Shuttle-Booking-Software v1.0 is vulnerable to SQL injection attacks. An attacker can exploit this vulnerability to steal information from the database.
Mitigation:
The vendor should sanitize the input for the location_id parameter to prevent SQL injection attacks.