Vulnerability Description
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Online Movie Ticket Booking System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/projectworldsofficial/Online-Movie-Ticket-Booking-System-in-pExploitIssue TrackingThird Party Advisory
- https://github.com/projectworldsofficial/Online-Movie-Ticket-Booking-System-in-pExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-44866?
CVE-2021-44866 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract...
How severe is CVE-2021-44866?
CVE-2021-44866 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44866?
Check the references section above for vendor advisories and patch information. Affected products include: Projectworlds Online Movie Ticket Booking System.