vendor:
Virtual Airlines Manager
by:
Pankaj Kumar Thakur
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Virtual Airlines Manager
Affected Version From: 2.6.2
Affected Version To: 2.6.2
Patch Exists: Yes
Related CWE: N/A
CPE: 2.6.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2020
Virtual Airlines Manager 2.6.2 – ‘notam’ SQL Injection
The 'notam_id' parameter in Virtual Airlines Manager 2.6.2 is vulnerable to SQL injection. The parameter's value is going into the SQL query directly, allowing an attacker to inject malicious code. Proof of concept can be found at https://localhost:8080/vam/index.php?page=notam¬am_id=11%27%27
Mitigation:
The vendor has released a patch to address the vulnerability. Users should update to the latest version of Virtual Airlines Manager.