SQL Injection Vulnerability in itsourcecode Pool of Bethesda Online Reservation System
CVE-2024-6371

9.8CRITICAL

Key Information:

Vendor
Janobe
Vendor
CVE Published:
27 June 2024

Summary

A significant SQL injection vulnerability exists within the itsourcecode Pool of Bethesda Online Reservation System, specifically found in the controller.php file. The vulnerability arises from improper handling of the argument rmtype_id, allowing attackers to manipulate SQL queries executed by the application. This manipulation can be performed remotely, putting systems at risk of unauthorized access and potential data compromise. The exploit has been publicly disclosed, escalating the urgency for affected users to apply patches or mitigations to protect their environments.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.