An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Jun 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Phpjabbers
Phpjabbers cinema Booking System |
|
CPEs | cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:* | |
Vendors & Products |
Phpjabbers
Phpjabbers cinema Booking System |
Thu, 06 Feb 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Thu, 06 Feb 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-02-06T00:00:00.000Z
Updated: 2025-02-06T21:23:45.597Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57430

Updated: 2025-02-06T16:44:23.950Z

Status : Analyzed
Published: 2025-02-06T17:15:20.717
Modified: 2025-06-24T00:12:38.623
Link: CVE-2024-57430

No data.