vendor:
Notilus travel solution software
by:
Alex Haynes
5.5
CVSS
MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
89
CWE
Product Name: Notilus travel solution software
Affected Version From: 2012 R3
Affected Version To: 2012 R3
Patch Exists: YES
Related CWE: NONE
CPE: NOTILUS_TRAVEL_SOLUTION_SOFTWARE
Platforms Tested:
2016
Notilus SQL injection
The Notilus software is vulnerable to SQL injection attacks, specifically in the password modification fields.
Mitigation:
Patch to latest available 2012 R3 branch or upgrade to version 2016.