A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.
References
Configurations
No configuration.
History
21 Aug 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-20 CWE-89 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
20 Aug 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-20 17:15
Updated : 2025-08-22 18:09
NVD link : CVE-2025-55444
Mitre link : CVE-2025-55444
CVE.ORG link : CVE-2025-55444
JSON object : View
Products Affected
No product.