PT-2025-5838 · Phpjabbers · Phpjabbers Cinema Booking System
Ahrixia
·
Published
2025-02-06
·
Updated
2025-06-24
·
CVE-2024-57429
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
PHPJabbers Cinema Booking System version 2.0
Description:
A cross-site request forgery (CSRF) vulnerability in the
pjActionUpdate function allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.Recommendations:
For PHPJabbers Cinema Booking System version 2.0, consider disabling the
pjActionUpdate function until a patch is available to prevent exploitation. Restrict access to this function to minimize the risk of privilege escalation. Avoid using this function in scenarios where an authenticated admin may be tricked into submitting unauthorized requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
LPE
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpjabbers Cinema Booking System