PT-2024-38387 · Unknown · Airline Reservation System

·

CVE-2024-7497

·

Published

2024-08-06

·

Updated

2024-08-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airline Reservation System version 1.0
Description A critical issue affects the processing of the file /admin/index.php, where the manipulation of the page argument leads to file inclusion. This can be initiated remotely.
Recommendations For Airline Reservation System version 1.0, consider restricting access to the /admin/index.php file until a fix is available. As a temporary workaround, avoid using the page argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7497

Affected Products

Airline Reservation System