First published: Fri Aug 09 2024(Updated: )
A vulnerability was found in code-projects Simple Ticket Booking 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file authenticate.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
code-projects Simple Ticket Booking | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7636 has been declared as a critical vulnerability.
To fix CVE-2024-7636, ensure that you validate and sanitize user inputs in the authenticate.php file to prevent SQL injection.
CVE-2024-7636 affects version 1.0 of code-projects Simple Ticket Booking.
CVE-2024-7636 is a SQL injection vulnerability that can be exploited through the email/password authentication parameters.
Exploiting CVE-2024-7636 could lead to unauthorized access to the application and exposure of sensitive data.