vendor:
VEO Transportation
by:
Sedric Louissaint
7,5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: VEO Transportation
Affected Version From: NovusEDU-2.2.x-XP_BB-20201123-184084
Affected Version To: VEO--20201123-184084
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows Server 2012 R2 Standard
2021
TripSpark VEO Transportation – ‘editOEN’ Blind SQL Injection
The POST body parameter editOEN is vulnerable to blind SQL injection. Any user can inject custom SQL commands into the “Student Busing Information” search queries. An exploit is not necessary to take advantage of this vulnerability.
Mitigation:
Ensure that all user-supplied input is validated and filtered before being used in SQL queries.