What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.
Explanation of Vulnerability in Simple Terms
VikRentCar versions up to 1.4.0 contain a SQL injection vulnerability in an unauthenticated network-accessible component. An attacker can craft malicious input to extract sensitive data from the database, including user credentials and rental information. The vulnerability requires no authentication or user interaction. Update to version 1.4.6 or later to remediate.
What an attacker can do
Extract sensitive data from the database, including user credentials and rental records.
Potential impact on your site
Rental customer data, user credentials, and business information can be stolen without warning or authentication.
Conditions required to exploit
Network access to the VikRentCar installation; no authentication required.
Key dates
External resources
Related vulnerabilities