PT-2026-81275 · Unknown · Liketrek Trek
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
liketrek TREK versions prior to 3.1.0
Description
An issue in the Journey Entry Update component allows for remote SQL injection. This occurs within the
journeyService.updateEntry() function located in the server/src/nest/journey/journey.controller.t file. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.Recommendations
Upgrade to version 3.1.0.
Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Liketrek Trek