Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc9h-wr8f-982q

Опубликовано: 10 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

EPSS

Процентиль: 53%
0.00296
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

EPSS

Процентиль: 53%
0.00296
Низкий

Дефекты

CWE-89