{"api_version":"1","generated_at":"2026-07-23T12:59:40+00:00","cve":"CVE-2023-2619","urls":{"html":"https://cve.report/CVE-2023-2619","api":"https://cve.report/api/cve/CVE-2023-2619.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-2619","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-2619"},"summary":{"title":"CVE-2023-2619","description":"A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects the function exec of the file disapprove_delete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228549 was assigned to this vulnerability.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-05-10 06:15:00","updated_at":"2023-11-07 04:12:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://vuldb.com/?id.228549","name":"https://vuldb.com/?id.228549","refsource":"MISC","tags":[],"title":"CVE-2023-2619: SourceCodester Online Tours & Travels Management System disapprove_delete.php exec sql injection","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://blog.csdn.net/weixin_43864034/article/details/130596916","name":"https://blog.csdn.net/weixin_43864034/article/details/130596916","refsource":"MISC","tags":[],"title":"SourceCodester Online Tours & Travels Management System disapprove_delete.php sql injection_@sec的博客-CSDN博客","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?ctiid.228549","name":"https://vuldb.com/?ctiid.228549","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-2619","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2619","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"2619","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"online_tours_\\&_travels_management_system_project","cpe5":"online_tours_\\&_travels_management_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-2619","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects the function exec of the file disapprove_delete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228549 was assigned to this vulnerability."},{"lang":"deu","value":"Es wurde eine kritische Schwachstelle in SourceCodester Online Tours & Travels Management System 1.0 gefunden. Betroffen hiervon ist die Funktion exec der Datei disapprove_delete.php. Mit der Manipulation des Arguments id mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-89 SQL Injection","cweId":"CWE-89"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"SourceCodester","product":{"product_data":[{"product_name":"Online Tours & Travels Management System","version":{"version_data":[{"version_affected":"=","version_value":"1.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.228549","refsource":"MISC","name":"https://vuldb.com/?id.228549"},{"url":"https://vuldb.com/?ctiid.228549","refsource":"MISC","name":"https://vuldb.com/?ctiid.228549"},{"url":"https://blog.csdn.net/weixin_43864034/article/details/130596916","refsource":"MISC","name":"https://blog.csdn.net/weixin_43864034/article/details/130596916"}]},"credits":[{"lang":"en","value":"mr_ruann (VulDB User)"}],"impact":{"cvss":[{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"},{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"},{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}]}},"nvd":{"publishedDate":"2023-05-10 06:15:00","lastModifiedDate":"2023-11-07 04:12:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:online_tours_\\&_travels_management_system_project:online_tours_\\&_travels_management_system:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}