Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2262

Опубликовано: 12 июл. 2022
Источник: nvd
CVSS3: 4.7
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The manipulation of the argument id with the input 2828%27%20AND%20(SELECT%203766%20FROM%20(SELECT(SLEEP(5)))BmIK)%20AND%20%27YLPl%27=%27YLPl leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:online_hotel_booking_project:online_hotel_booking:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00261
Низкий

4.7 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The manipulation of the argument id with the input 2828%27%20AND%20(SELECT%203766%20FROM%20(SELECT(SLEEP(5)))BmIK)%20AND%20%27YLPl%27=%27YLPl leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 49%
0.00261
Низкий

4.7 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89