Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Online Tours & Travels Management System — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Online Tours & Travels Management System, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses associated with the Online Tours & Travels Management System, a software product used by travel agencies and tour operators to manage bookings and customer data. The vulnerabilities listed here represent a curated aggregation of known issues identified by various vendors, independent researchers, and security tracking organizations. This collection encompasses diverse weakness types, including injection flaws, authentication bypasses, and insecure direct object references, affecting different components of the travel management platform. The data presented covers security advisories and vulnerability reports from January 2018 through December 2023, providing a historical view of the product’s security posture over a five-year period. By reviewing this information, users can track the publication timeline of specific vendor advisories related to this system, gaining insight into how and when specific flaws were disclosed and patched. Additionally, security professionals can use this resource to understand the prevalence and impact of specific weakness classes within the context of travel industry software, helping to prioritize mitigation efforts for similar architectures. Readers can also look up the comprehensive vulnerability history of the Online Tours & Travels Management System to assess long-term risk exposure and evaluate the effectiveness of past security updates. This aggregation serves as a centralized reference point for understanding the security landscape of this specific product, facilitating informed decision-making for IT administrators, security auditors, and developers involved in the deployment or maintenance of such systems. The goal is to provide transparent, factual data without speculation or promotional content.

Vendor: SourceCodester

CVE IDTitleCVSSSeverityPublished
CVE-2024-2168 SourceCodester Online Tours & Travels Management System HTTP POST Request expense_category.php sql injection CWE-89 4.7 Medium2024-03-04
CVE-2024-0884 SourceCodester Online Tours & Travels Management System payment.php exec sql injection CWE-89 4.7 Medium2024-01-25
CVE-2024-0883 SourceCodester Online Tours & Travels Management System pay.php prepare sql injection CWE-89 6.3 Medium2024-01-25
CVE-2024-0735 SourceCodester Online Tours & Travels Management System expense.php exec sql injection CWE-89 6.3 Medium2024-01-19
CVE-2023-6765 SourceCodester Online Tours & Travels Management System email_setup.php prepare sql injection CWE-89 5.5 Medium2023-12-13
CVE-2023-4866 SourceCodester Online Tours & Travels Management System booking.php exec sql injection CWE-89 6.3 Medium2023-09-09
CVE-2023-2619 SourceCodester Online Tours & Travels Management System disapprove_delete.php exec sql injection CWE-89 6.3 Medium2023-05-10
CVE-2023-1590 SourceCodester Online Tours & Travels Management System currency.php exec sql injection CWE-89 6.3 Medium2023-03-23
CVE-2023-1589 SourceCodester Online Tours & Travels Management System approve_delete.php exec sql injection CWE-89 6.3 Medium2023-03-23
CVE-2023-1396 SourceCodester Online Tours & Travels Management System traveller_details.php cross site scripting CWE-79 3.5 Low2023-03-14
CVE-2023-1391 SourceCodester Online Tours & Travels Management System ab.php unrestricted upload CWE-434 4.7 Medium2023-03-14
CVE-2023-0570 SourceCodester Online Tours & Travels Management System payment_operation.php sql injection CWE-89 6.3 Medium2023-01-29
CVE-2023-0561 SourceCodester Online Tours & Travels Management System s.php sql injection CWE-89 6.3 Medium2023-01-28
CVE-2023-0560 SourceCodester Online Tours & Travels Management System practice_pdf.php sql injection CWE-89 4.7 Medium2023-01-28
CVE-2023-0534 SourceCodester Online Tours & Travels Management System expense_report.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0533 SourceCodester Online Tours & Travels Management System expense_report.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0532 SourceCodester Online Tours & Travels Management System disapprove_user.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0531 SourceCodester Online Tours & Travels Management System booking_report.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0530 SourceCodester Online Tours & Travels Management System approve_user.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0529 SourceCodester Online Tours & Travels Management System add_payment.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0528 SourceCodester Online Tours & Travels Management System abc.php sql injection CWE-89 4.7 Medium2023-01-27
CVE-2023-0516 SourceCodester Online Tours & Travels Management System Parameter forget_password.php sql injection CWE-89 5.5 Medium2023-01-26
CVE-2023-0515 SourceCodester Online Tours & Travels Management System Parameter forget_password.php sql injection CWE-89 5.5 Medium2023-01-26
CVE-2023-0324 SourceCodester Online Tours & Travels Management System page-login.php sql injection CWE-89 7.3 High2023-01-16

All 24 known CVE vulnerabilities affecting Online Tours & Travels Management System with full Chinese analysis, references, and POCs where available.