First published: Fri Jan 06 2023(Updated: )
SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Theme Park Ticketing System Project Theme Park Ticketing System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40049 is a SQL injection vulnerability in the sourcecodester Theme Park Ticketing System 1.0.
CVE-2022-40049 allows remote attackers to view sensitive information by exploiting the SQL injection vulnerability in the system's /tpts/manage_user.php page.
The severity of CVE-2022-40049 is high, with a CVSS score of 7.5 (out of 10).
An attacker can exploit CVE-2022-40049 by sending specially crafted requests to the /tpts/manage_user.php page with a malicious id parameter.
Yes, to fix CVE-2022-40049, it is recommended to apply the latest security patch or update for the sourcecodester Theme Park Ticketing System.