CVE-2025-7456: Campcodes Online Movie Theater Seat Reservation System reserve.php sql injection
A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this issue is some unknown functionality of the file /reserve.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7456?
CVE-2025-7456 is classified as a critical vulnerability.
How does CVE-2025-7456 affect the Campcodes Online Movie Theater Seat Reservation System?
CVE-2025-7456 affects the reservation functionality in the file /reserve.php, leading to potential SQL injection.
What are the potential risks associated with CVE-2025-7456?
Exploitation of CVE-2025-7456 may allow attackers to execute unauthorized SQL commands against the database.
How do I fix CVE-2025-7456?
To fix CVE-2025-7456, sanitize and validate input parameters, especially the ID argument, in the /reserve.php file.
Can I still use the Campcodes Online Movie Theater Seat Reservation System if CVE-2025-7456 is present?
Using the system with CVE-2025-7456 is risky as it exposes the application to SQL injection attacks, and immediate mitigation is recommended.