CVE-2023-54359
Published
CVSS v3
8.2
HIGH
CVSS v2
N/A
Affected
1
PROJECT
Description
WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted 'pid' values using XOR-based payloads to extract sensitive database information or cause denial of service.
<p><strong>Travon Travel Plugin</strong> allows your customers to input their travel requirements and send them to you via email. It functions as a lead management system integrated with CRM. Subsequently, you can reach out to the customer, invoice them for the services, and proceed to issue the requested services. Easy upgrade the plugin to a booking engine or connect the prefered supplier, consolidator, GDS or Bedbanks. <strong>Scale as you grow!</strong></p>
<h3>Preview and Setup Documentations</h3>
<p><a href="https://www.travon-wp.com/white-label.html" rel="nofollow ugc">Preivew Meta Search Portal</a></p>
<h4>ShortCodes</h4>
<ul>
<li><strong>[travon_searchBox]</strong> Shortcodes for the search box</li>
</ul>
<h4>Integration with Existing WordPress Theme</h4>
<ul>
<li>Login to your WordPress Admin</li>
<li>Use the [travon_searchBox] to create the searchbox in your home page, somewhere on banner. </li>
<li>Its Done! You can now browse the page and search. if you face any issue, you can WhatsApp our Travel Meta Support Team at +91 8882170162</li>
</ul>
<h3>Find us on Themeforest.net – Travel Meta Search</h3>
<p><strong>WordPress Travon Theme</strong>, the premium compatible theme for adivaha plugins with default Travel Meta Search Engine. <a href="https://themeforest.net/item/travon-tour-and-hotel-booking-wordpress-theme/44265539" rel="nofollow ugc">Buy from Themeforest.net</a> or <a href="https://www.templatemonster.com/wordpress-themes/adivaha-themes-tour-and-hotel-booking-affiliate-theme-324826.html" rel="nofollow ugc">Buy from TemplateMonster.com</a></p>
<h4>Third Party API Integrations</h4>
<p>Need <em>more power</em>? Connect the premium plugin with the supplier of your choice under your contracting and use your direct connections for real-time bookings. Few of the suppliers pre-integrated are:</p>
<ul>
<li>Amadeus (Provider)</li>
<li>Amadeus (Self Service and Enterprise)</li>
<li>Travelport Galileo</li>
<li>AirArabia (NDC)</li>
<li>TravelFusion (NDC)</li>
<li>LIFT Airlines (NDC)</li>
<li>Mahan Airlines (NDC)</li>
<li>BADR Airlines (NDC)</li>
<li>FlyDubai (NDC)</li>
<li>AirGateway (NDC Platform)</li>
<li>Hotelbeds/Bedsonline/GTA</li>
<li>Travel Boutique Online (TBO)</li>
<li>RateHawk</li>
<li>Flyshop</li>
<li>SAN Travels</li>
<li>VIA.com</li>
<li>KIWI Flights</li>
<li>Duffel</li>
<li>Mondee Holdings (TripPro)</li>
<li>TravelPayouts</li>
<li>Restel</li>
<li>Viator (TripAdvisor)</li>
<li>GetYourGuide</li>
<li>Restel</li>
<li>Rezlive</li>
<li>Musement</li>
<li>EaseMyTrip</li>
<li>AirIQ</li>
<li>GoFlySmart</li>
<li>MystiFly</li>
<li>Bridgify</li>
<li>Agoda</li>
<li>Cartrawler</li>
<li>Passport Online Cruises</li>
<li>PARTO CRS</li>
<li>[and Counting …]</li>
</ul>
<h4>Support</h4>
<p>Drop us your questions or need assistance <a href="https://www.travon-wp.com/contact-us.html" rel="nofollow ugc">Travon contact</a> or your can email us your questions directly at [email protected]</p>
<h4>Follow Us</h4>
<ul>
<li><strong>Official Website</strong> – <a href="https://www.travon-wp.com/" rel="nofollow ugc">https://www.travon-wp.com/</a> </li>
<li><strong>Facebook Page</strong> – <a href="https://adivaha.io/1sW2S40YW" rel="nofollow ugc">https://www.facebook.com/profile.php?id=61582450888789</a></li>
<li><strong>Instagram Account</strong> – <a href="https://www.instagram.com/travon.wp.official/" rel="nofollow ugc">https://www.instagram.com/travon.wp.official/</a></li>
<li><strong>Linkedin Account</strong> – <a href="https://www.linkedin.com/company/travon-wp/" rel="nofollow ugc">https://www.linkedin.com/company/travon-wp/</a></li>
<li><strong>YouTube</strong> – <a href="https://www.youtube.com/@Travon-WP-official" rel="nofollow ugc">https://www.youtube.com/@Travon-WP-official</a></li>
<li><strong>Themeforest.net</strong> – <a href="https://themeforest.net/item/travon-tour-and-hotel-booking-wordpress-theme/44265539" rel="nofollow ugc">https://themeforest.net/item/travon-tour-and-hotel-booking-wordpress-theme/44265539</a></li>
</ul>