PT-2026-30425 · Code Projects · Concert Ticket Reservation System

Wenzhuolin

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5555

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Concert Ticket Reservation System version 1.0
Description A weakness exists in the code-projects Concert Ticket Reservation System 1.0. The issue affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php within the Parameter Handler component. Manipulation of the Email argument can lead to SQL injection. The attack can be launched remotely, and the exploit has been made publicly available.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /ConcertTicketReservationSystem-master/login.php file.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5555

Affected Products

Concert Ticket Reservation System