VYPR

Online Tours \& Travels Management System

by Mayurik

CVEs (6)

  • CVE-2024-48411CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.

  • CVE-2024-6471MedJul 3, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an unknown part of the file sms_setting.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2024-0883MedJan 25, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare of the file admin/pay.php. The manipulation of the argument id leads to sql injection. The attack can be…

  • CVE-2024-0735MedJan 19, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. Affected by this issue is the function exec of the file admin/operations/expense.php. The manipulation leads to sql injection. The attack may be launched…

  • CVE-2023-6765MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been…

  • CVE-2024-2168MedMar 4, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/operations/expense_category.php of the component HTTP POST Request Handler. The manipulation of the…