Vulnerabilities > Projectworlds > Railway Reservation System > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-21 CVE-2023-48689 SQL Injection vulnerability in Projectworlds Railway Reservation System 1.0
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfiltered to the database.
network
low complexity
projectworlds CWE-89
critical
9.8
2023-12-21 CVE-2023-48687 SQL Injection vulnerability in Projectworlds Railway Reservation System 1.0
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database.
network
low complexity
projectworlds CWE-89
critical
9.8
2023-12-21 CVE-2023-48685 SQL Injection vulnerability in Projectworlds Railway Reservation System 1.0
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
network
low complexity
projectworlds CWE-89
critical
9.8