CVE-2023-50867

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
04/01/2024
Last modified:
10/01/2024

Description

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kashipara:travel_website:1.0:*:*:*:*:*:*:*