Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-58410
HistoryJul 15, 2022 - 12:00 a.m.

Projectworlds Online Hotel Booking System SQL注入漏洞(CNVD-2022-58410)

2022-07-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
21
projectworlds
online hotel booking system
sql injection
cnvd-2022-58410
validation
roomname parameter
external input
attacker
vulnerability
attack

EPSS

0.001

Percentile

41.1%

A SQL injection vulnerability exists in Projectworlds Online Hotel Booking System version 1.0, a hotel online booking system from Projectworlds, Inc. The vulnerability stems from a lack of validation of the roomname parameter against external input SQL statements. An attacker could use this vulnerability to perform a sql injection attack.

EPSS

0.001

Percentile

41.1%

Related for CNVD-2022-58410