CVE-2023-50862

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 4, 2024
Updated: Jan 10, 2024
CWE ID 89

Summary

CVE-2023-50862 is a vulnerability affecting Travel Website version 1.0. This issue involves multiple unauthenticated SQL injection vulnerabilities. Specifically, the 'hotelIDHidden' parameter in the booking.php resource fails to validate user input, allowing malicious characters to be sent directly to the database without filtering. This flaw can potentially enable attackers to execute malicious SQL queries and gain unauthorized access to sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share