SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/Manba6/Bug_report/blob/main/vendors/oretnom23/theme-park-ticketing-system/SQLi-1.md | Exploit Third Party Advisory | 
| https://github.com/Manba6/Bug_report/blob/main/vendors/oretnom23/theme-park-ticketing-system/SQLi-1.md | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 07:20
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-01-06 03:15
Updated : 2025-04-10 14:15
NVD link : CVE-2022-40049
Mitre link : CVE-2022-40049
CVE.ORG link : CVE-2022-40049
JSON object : View
Products Affected
                theme_park_ticketing_system_project
- theme_park_ticketing_system
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
