A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare of the file admin/pay.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252034 is the identifier assigned to this vulnerability.
History

Thu, 29 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-01-25T19:00:07.377Z

Updated: 2025-05-29T15:19:11.384Z

Reserved: 2024-01-25T13:31:28.388Z

Link: CVE-2024-0883

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.905Z

cve-icon NVD

Status : Modified

Published: 2024-01-25T19:15:08.940

Modified: 2024-11-21T08:47:36.130

Link: CVE-2024-0883

cve-icon Redhat

No data.