Blind SQL Injection Vulnerability in Pinpoint Booking System
CVE-2024-53815
8.5HIGH
Summary
A security vulnerability exists within the Pinpoint Booking System provided by PINPOINT.WORLD, characterized as an SQL Injection flaw. This vulnerability allows attackers to execute unapproved SQL commands through input fields, potentially leading to unauthorized access to sensitive data. Affected versions include those from n/a to 2.9.9.5.1. It is crucial for users and administrators of the Pinpoint Booking System to implement mitigations promptly to safeguard against potential exploitation.
Affected Version(s)
Pinpoint Booking System <= 2.9.9.5.1
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)