Fiche vulnérabilité
CVE-2024-32125 : faille élevée ba-booking ba book everything (CVSS 8.8)
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 15 avr. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- ba-booking ba book everything