SQL Injection Vulnerability in CodeAstro Car Rental System
CVE-2024-12981

5.3MEDIUM

Key Information:

Vendor
Codeastro
Status
Car Rental System
Vendor
CVE Published:
27 December 2024

Badges

👾 Exploit Exists🟡 Public PoC

Summary

A vulnerability has been identified in the CodeAstro Car Rental System 1.0, specifically within the functionality of the file /bookingconfirm.php. This issue arises from inadequate validation of user-supplied input within the driver_id_from_dropdown parameter, allowing attackers to execute SQL injection attacks. These types of vulnerabilities can be exploited remotely, enabling unauthorized access to sensitive data. It is crucial for users of the CodeAstro Car Rental System to apply necessary safeguards and updates as other parameters may also be susceptible to similar attacks. The exploit has been publicly disclosed, highlighting the urgency for remediation.

Affected Version(s)

Car Rental System 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

user3306 (VulDB User)
.