Описание
A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:vishalmathur:online_artwork_and_fine_arts_project:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.0044
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-20
EPSS
Процентиль: 63%
0.0044
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-20