← Back to CVE List

CVE-2023-50862

Published: 2024-01-04T15:15Z
Last Modified: 2024-11-21T08:37Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt