cvelist/2024/7xxx/CVE-2024-7498.json
2024-08-06 03:00:33 +00:00

110 lines
4.0 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-7498",
"ASSIGNER": "cna@vuldb.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273624."
},
{
"lang": "deu",
"value": "Es wurde eine kritische Schwachstelle in itsourcecode Airline Reservation System 1.0 ausgemacht. Betroffen hiervon ist die Funktion login/login2 der Datei /admin/login.php der Komponente Admin Login Page. Durch Beeinflussen des Arguments username mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff \u00fcber das Netzwerk. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-89 SQL Injection",
"cweId": "CWE-89"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "itsourcecode",
"product": {
"product_data": [
{
"product_name": "Airline Reservation System",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "1.0"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://vuldb.com/?id.273624",
"refsource": "MISC",
"name": "https://vuldb.com/?id.273624"
},
{
"url": "https://vuldb.com/?ctiid.273624",
"refsource": "MISC",
"name": "https://vuldb.com/?ctiid.273624"
},
{
"url": "https://vuldb.com/?submit.385894",
"refsource": "MISC",
"name": "https://vuldb.com/?submit.385894"
},
{
"url": "https://github.com/DeepMountains/zzz/blob/main/CVE1-3.md",
"refsource": "MISC",
"name": "https://github.com/DeepMountains/zzz/blob/main/CVE1-3.md"
}
]
},
"credits": [
{
"lang": "en",
"value": "quad (VulDB User)"
}
],
"impact": {
"cvss": [
{
"version": "3.1",
"baseScore": 7.3,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "3.0",
"baseScore": 7.3,
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "2.0",
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
}
]
}
}