CVE Details
Basic Information
| Title | code-projects Movie Ticketing System logIn.php sql injection |
|---|---|
| Type | cve |
| Published | 2025-06-30T05:32:06.253Z |
| Last Seen |
Product Information
| Vendor | code-projects |
|---|---|
| Product | Movie Ticketing System |
| Version | 1.0 |
CVSS Information
| Base Score | 6.9 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A SQL injection vulnerability in the logIn.php file of the Movie Ticketing System allows remote attackers to inject malicious SQL code via the postName argument, potentially leading to unauthorized data access and manipulation. |
|---|---|
| AI Severity | Medium |
| Vendor | code-projects |
| Product | Movie Ticketing System |
| Affected Version | 1.0 |
Affected Products
- code-projects Movie Ticketing System 1.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-89, CWE-74 |
| Bulletin Family |
References
Description
A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /logIn.php. The manipulation of the argument postName leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.