SQL Injection Vulnerability in SourceCodester Online Hotel Reservation System
CVE-2024-10411
7.2HIGH
What is CVE-2024-10411?
A significant vulnerability has been discovered in the SourceCodester Online Hotel Reservation System version 1.0, specifically within the functions doCancelRoom, doCancel, doConfirm, doCancel, doCheckin, and doCheckout in the controller.php file located in the admin module. This vulnerability permits an attacker to manipulate the id argument, leading to potential SQL injection. With the ability to execute this attack remotely, the disclosure of exploit details to the public highlights an urgent need for affected users to implement immediate security measures to protect their systems from unauthorized access or data breaches.
Affected Version(s)
Online Hotel Reservation System 1.0