CVE-2026-5554: code-projects Concert Ticket Reservation System Parameter process_search.php sql injection
A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/processsearch.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5554?
The severity of CVE-2026-5554 is medium with a score of 6.9.
How do I fix CVE-2026-5554?
To fix CVE-2026-5554, validate and sanitize all user inputs, particularly in the process_search.php file.
What type of vulnerability is CVE-2026-5554?
CVE-2026-5554 is classified as an SQL Injection vulnerability.
What component is affected by CVE-2026-5554?
CVE-2026-5554 affects the Parameter Handler component in the Code-projects Concert Ticket Reservation System.
What version of the software is impacted by CVE-2026-5554?
CVE-2026-5554 impacts version 1.0 of the Code-projects Concert Ticket Reservation System.