PT-2025-27408 · Unknown · Code-Projects Movie Ticketing System

Meraklbz

·

Publicado

2025-06-30

·

Atualizado

2025-07-05

·

CVE-2025-6889

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: code-projects Movie Ticketing System version 1.0
Description: A critical issue has been discovered, affecting the /logIn.php file. The manipulation of the postName argument leads to SQL injection. This issue can be exploited remotely.
Recommendations: For code-projects Movie Ticketing System version 1.0, consider restricting access to the /logIn.php file until a fix is available. As a temporary workaround, avoid using the postName argument in the affected file to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-6889

Produtos afetados

Code-Projects Movie Ticketing System