vendor:
Virtual Airlines Manager
by:
Mosaaed
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Virtual Airlines Manager
Affected Version From: 2.6.2
Affected Version To: 2.6.2
Patch Exists: NO
Related CWE: N/A
CPE: a:virtual_airlines_manager:virtual_airlines_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2020
Virtual Airlines Manager 2.6.2 – ‘id’ SQL Injection
SQL Injection vulnerability exists in Virtual Airlines Manager 2.6.2. An attacker can inject malicious SQL queries via the 'id' parameter in the URL. For example, an attacker can inject malicious SQL queries via the 'registry_id', 'plane_icao', 'hub_id', 'plane_location' and 'event_id' parameters in the URL.
Mitigation:
Input validation should be performed to prevent SQL injection attacks. Parameterized queries should be used to prevent SQL injection attacks.