CVE-2022-32024
Car Rental Management System 1.0 - SQL Injection
Record summary
CVE-2022-32024 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHCar Rental Management System 1.0 - SQL InjectionCVSS 7.2
Car Rental Management System 1.0 contains an SQL injection vulnerability via /booking.php?car_id=. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or even complete compromise of the system.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the Car Rental Management System 1.0.
Source: ProjectDiscovery