First published: Thu Feb 06 2025(Updated: )
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Cinema Booking System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57428 is classified as a stored cross-site scripting (XSS) vulnerability with a high severity level.
To fix CVE-2024-57428, implement input validation and sanitization for all user-uploaded files and configurations in the PHPJabbers Cinema Booking System.
CVE-2024-57428 affects PHPJabbers Cinema Booking System v2.0 due to vulnerabilities in file upload fields and seat number configurations.
The impacts of CVE-2024-57428 include the potential for attackers to inject persistent JavaScript, leading to phishing attacks and unauthorized actions.
Any attacker with access to the input fields in the PHPJabbers Cinema Booking System can exploit CVE-2024-57428 to execute persistent cross-site scripting.