vendor:
JHotelReservation
by:
Ihsan Sencan
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: JHotelReservation
Affected Version From: 6.0.7
Affected Version To: 6.0.7
Patch Exists: NO
Related CWE:
CPE: a:jhotelreservation_project:jhotelreservation:6.0.7
Platforms Tested: Windows 7 (x64), Kali Linux (x64)
2019
Joomla! Component JHotelReservation 6.0.7 – SQL Injection
The Joomla! Component JHotelReservation version 6.0.7 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending a specially crafted POST request to the search-hotels endpoint, allowing them to execute arbitrary SQL queries on the underlying database.
Mitigation:
The vendor has not provided a patch for this vulnerability. Users are advised to update to the latest version of the component and sanitize user input to prevent SQL Injection attacks.