Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-88262
HistorySep 28, 2022 - 12:00 a.m.

Online Tours

2022-09-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
online tours
travels
management system
sql injection
vulnerability
mayuri k
exploit
sensitive information

0.001 Low

EPSS

Percentile

37.7%

Online Tours & Travels Management System is an online travel management system from the personal developer Mayuri K. A SQL injection vulnerability exists in Online Tours & Travels Management System v1.0, which stems from a lack of validation of externally entered SQL statements in the id parameter of its /admin/update_expense.php component. An attacker could exploit the vulnerability to obtain sensitive database information.

0.001 Low

EPSS

Percentile

37.7%

Related for CNVD-2022-88262