CVE-2024-57430

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*

History

24 Jun 2025, 00:12

Type Values Removed Values Added
CPE cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad de inyección SQL en la función pjActionGetUser de PHPJabbers Cinema Booking System v2.0 permite a los atacantes manipular las consultas de la base de datos a través del parámetro de columna. La explotación de esta falla puede dar lugar a la divulgación no autorizada de información, la escalada de privilegios o la manipulación de la base de datos.
References () https://github.com/ahrixia/CVE-2024-57430 - () https://github.com/ahrixia/CVE-2024-57430 - Exploit, Third Party Advisory
References () https://www.phpjabbers.com/cinema-booking-system/ - () https://www.phpjabbers.com/cinema-booking-system/ - Product
First Time Phpjabbers
Phpjabbers cinema Booking System

06 Feb 2025, 22:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 17:15

Updated : 2025-06-24 00:12


NVD link : CVE-2024-57430

Mitre link : CVE-2024-57430

CVE.ORG link : CVE-2024-57430


JSON object : View

Products Affected

phpjabbers

  • cinema_booking_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')