Railway Reservation System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-48689
9.8CRITICAL
What is CVE-2023-48689?
The Railway Reservation System v1.0 is susceptible to multiple unauthenticated SQL injection vulnerabilities. Specifically, the 'byname' parameter within the train.php file fails to appropriately validate incoming characters. As a result, unfiltered input can be directly sent to the database, allowing potential attackers to manipulate queries and compromise the database integrity.
Affected Version(s)
Railway Reservation System 1.0