PT-2025-18275 · Unknown · Phpgurukul Park Ticketing Management System
CVE-2025-45017
·
Publicado
2025-04-30
·
Atualizado
2025-04-30
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHPGurukul Park Ticketing Management System version 2.0
Description
A SQL injection issue was discovered in the edit-ticket.php file. This issue allows remote attackers to execute arbitrary code via the
tprice parameter in a POST request. The general information about the issue indicates it affects the PHPGurukul Park Ticketing Management System, specifically through the edit-ticket.php file.Recommendations
For PHPGurukul Park Ticketing Management System version 2.0, consider restricting access to the
edit-ticket.php file until a patch is available, and avoid using the tprice parameter in POST requests to the affected endpoint.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phpgurukul Park Ticketing Management System