Executive brief
A critical security vulnerability has been identified in Moderec Tourtella, a software solution used for managing tours and travel operations. This flaw allows unauthorized individuals to manipulate the underlying database via the internet without needing a password. Successful exploitation could lead to the theft of sensitive customer data, unauthorized modification of records, or a complete shutdown of the service.
Technical details
A SQL injection vulnerability (CWE-89) exists in Moderec Tourtella due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application over the network. Because the application fails to properly sanitize this input, the attacker can execute arbitrary SQL queries against the backend database. This can result in full data exfiltration, unauthorized data modification, or denial of service. The issue is resolved in versions released on or after May 26, 2025.
Affected products
- Moderec Tourtella before 26.05.2025
Timeline
- 2025-07-24: disclosed
- 2025-07-24: advisory
- 2025-05-26: patched: Fixed in version 26.05.2025