vendor:
Booking System
by:
Özkan Mustafa Akkus (AkkuS)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Booking System
Affected Version From: 5.5
Affected Version To: 5.5
Patch Exists: YES
Related CWE: N/A
CPE: a:codecanyon:booking_system:5.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
BookingWizz Booking System 5.5 – ‘bs-services-add.php’ SQL Injection
The service editing on the admin panel is vulnerable. An attacker can exploit the entire database using this vulnerable in the 'id' parameter. The payload is a MySQL >= 5.0 boolean-based blind - Parameter replace.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.