Online Bus Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-45015
9.8CRITICAL
What is CVE-2023-45015?
The Online Bus Booking System v1.0 has multiple vulnerabilities due to improper validation of the 'date' parameter in the bus_info.php file. This allows attackers to exploit the system by sending crafted input directly to the database without any authentication. The lack of filtering means malicious SQL code can be executed, leading to potential data disclosure or corruption.
Affected Version(s)
Online Bus Booking System 1.0