CVE-2024-57430

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-06 17:15

Updated : 2025-06-24 00:12


NVD link : CVE-2024-57430

Mitre link : CVE-2024-57430

CVE.ORG link : CVE-2024-57430


JSON object : View

Products Affected

phpjabbers

  • cinema_booking_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')