Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Online Tours & Travels Management System — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Online Tours & Travels Management System, with AI-generated Chinese analysis, references, and POCs.

This page aggregates public security weaknesses affecting the Online Tours & Travels Management System, a commercial software solution for managing travel bookings, itineraries, and customer data. It serves as a centralized resource for identifying known flaws within this specific vendor’s ecosystem, focusing on common vulnerability classifications such as cross-site scripting, SQL injection, and authentication bypasses. The content here collects reports and advisories published over the last several years, ensuring that historical and recent security incidents are readily accessible for analysis. Researchers and security professionals can use this collection to track a vendor’s advisory history, gaining insight into their responsiveness and remediation practices. By examining the specific weaknesses associated with this platform, users can understand the broader implications of each vulnerability class on similar travel management applications. Additionally, the page allows for looking up a product’s vulnerability history, providing a chronological view of how security issues have emerged and been addressed over time. This structured approach helps stakeholders assess risk profiles without needing to sift through scattered external sources. The data is curated to highlight patterns in code quality and configuration errors, offering a clearer picture of the attack surface exposed by this system. Users seeking to evaluate the overall security posture of the Online Tours & Travels Management System will find a consolidated view of known issues, facilitating better decision-making for procurement, audit, and patch management processes.

Vendor: SourceCodester

CVE IDTitleCVSSSeverityPublished
CVE-2024-2168 SourceCodester Online Tours & Travels Management System HTTP POST Request expense_category.php sql injection CWE-89 4.7 Medium2024-03-04
CVE-2024-0884 SourceCodester Online Tours & Travels Management System payment.php exec sql injection CWE-89 4.7 Medium2024-01-25
CVE-2024-0883 SourceCodester Online Tours & Travels Management System pay.php prepare sql injection CWE-89 6.3 Medium2024-01-25
CVE-2024-0735 SourceCodester Online Tours & Travels Management System expense.php exec sql injection CWE-89 6.3 Medium2024-01-19
CVE-2023-6765 SourceCodester Online Tours & Travels Management System email_setup.php prepare sql injection CWE-89 5.5 Medium2023-12-13
CVE-2023-4866 SourceCodester Online Tours & Travels Management System booking.php exec sql injection CWE-89 6.3 Medium2023-09-09
CVE-2023-2619 SourceCodester Online Tours & Travels Management System disapprove_delete.php exec sql injection CWE-89 6.3 Medium2023-05-10
CVE-2023-1590 SourceCodester Online Tours & Travels Management System currency.php exec sql injection CWE-89 6.3 Medium2023-03-23
CVE-2023-1589 SourceCodester Online Tours & Travels Management System approve_delete.php exec sql injection CWE-89 6.3 Medium2023-03-23
CVE-2023-1396 SourceCodester Online Tours & Travels Management System traveller_details.php cross site scripting CWE-79 3.5 Low2023-03-14
CVE-2023-1391 SourceCodester Online Tours & Travels Management System ab.php unrestricted upload CWE-434 4.7 Medium2023-03-14
CVE-2023-0570 SourceCodester Online Tours & Travels Management System payment_operation.php sql injection CWE-89 6.3 Medium2023-01-29
CVE-2023-0561 SourceCodester Online Tours & Travels Management System s.php sql injection CWE-89 6.3 Medium2023-01-28
CVE-2023-0560 SourceCodester Online Tours & Travels Management System practice_pdf.php sql injection CWE-89 4.7 Medium2023-01-28
CVE-2023-0534 SourceCodester Online Tours & Travels Management System expense_report.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0533 SourceCodester Online Tours & Travels Management System expense_report.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0532 SourceCodester Online Tours & Travels Management System disapprove_user.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0531 SourceCodester Online Tours & Travels Management System booking_report.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0530 SourceCodester Online Tours & Travels Management System approve_user.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0529 SourceCodester Online Tours & Travels Management System add_payment.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0528 SourceCodester Online Tours & Travels Management System abc.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0516 SourceCodester Online Tours & Travels Management System Parameter forget_password.php sql injection CWE-89 5.5 Medium2023-01-26
CVE-2023-0515 SourceCodester Online Tours & Travels Management System Parameter forget_password.php sql injection CWE-89 5.5 Medium2023-01-26
CVE-2023-0324 SourceCodester Online Tours & Travels Management System page-login.php sql injection CWE-89 7.3 High2023-01-16

All 24 known CVE vulnerabilities affecting Online Tours & Travels Management System with full Chinese analysis, references, and POCs where available.