← Back to CVE List

CVE-2024-48245

Published: 2025-01-07T16:15Z
Last Modified: 2025-01-07T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which are present in /newvehicle.php and /newdriver.php. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt