First published: Thu Sep 28 2023(Updated: )
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.
Credit: help@fluidattacks.com help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Online Movie Ticket Booking System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-44163 is critical with a value of 9.8.
CVE-2023-44163 affects the 'search' parameter in the process_search.php resource by not validating the characters received and sending them unfiltered to the database.
The software version 1.0 of Projectworlds Online Movie Ticket Booking System is affected by CVE-2023-44163.
Yes, there are references and advisories related to CVE-2023-44163. They can be found at https://fluidattacks.com/advisories/starr and https://projectworlds.in/.
The CWE ID for CVE-2023-44163 is 89.