ZeroHour

CVE-2021-44866

PoC
CVSS 3.1
7.5 high
EPSS
1%p61
Published
()
Modified
Description

An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

Vendors
projectworlds
Products
online movie ticket booking system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.