vendor:
Car Rental System
by:
TAD GROUP
9
CVSS
CRITICAL
Unescaped Parameter
N/A
CWE
Product Name: Car Rental System
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Car Rental System v2.5
An unescaped parameter was found in Car Rental System v2.5 (WP plugin). An attacker can exploit this vulnerability to read from the database. The POST parameters 'pickuploc', 'dropoffloc', and 'car_type' are vulnerable.
Mitigation:
The vendor has not released a patch yet.