CVE-2024-57427

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*

History

24 Jun 2025, 00:13

Type Values Removed Values Added
References () https://github.com/ahrixia/CVE-2024-57427 - () https://github.com/ahrixia/CVE-2024-57427 - Exploit, Third Party Advisory
References () https://www.phpjabbers.com/cinema-booking-system/ - () https://www.phpjabbers.com/cinema-booking-system/ - Product
First Time Phpjabbers
Phpjabbers cinema Booking System
Summary
  • (es) PHPJabbers Cinema Booking System v2.0 es vulnerable a cross-site scripting (XSS) reflejado. Varios puntos finales gestionan incorrectamente la entrada del usuario, lo que permite que se ejecuten secuencias de comandos maliciosas en el navegador de la víctima. Los atacantes pueden manipular enlaces maliciosos para robar cookies de sesión o realizar ataques de phishing.
CPE cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*

06 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 17:15

Updated : 2025-06-24 00:13


NVD link : CVE-2024-57427

Mitre link : CVE-2024-57427

CVE.ORG link : CVE-2024-57427


JSON object : View

Products Affected

phpjabbers

  • cinema_booking_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')