CVE-2024-25316
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 9, 2024
Updated: Aug 19, 2024
CWE ID 89
Summary
CVE-2024-25316: A SQL injection vulnerability has been identified in the Code-projects Hotel Management System 1.0. This issue can be exploited through the 'eid' parameter in the URL 'Hotel/admin/usersettingdel.php?eid=2'. An attacker can inject malicious SQL queries, potentially gaining unauthorized access to sensitive data or making unintended modifications to the database. System administrators should immediately patch or upgrade their installations to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Hotel Management System Project