CVE-2022-40098 | Online Tours & Travels Management System 1.0 update_expense.php ID sql injection
A vulnerability, which was classified as critical, was found in Online Tours & Travels Management System 1.0. This affects an unknown part of the file /admin/update_expense.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2022-40098. It is possible to initiate the attack remotely. There is no exploit available.