CVE-2024-57429

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*

History

24 Jun 2025, 00:13

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site request forgery (CSRF) en la función pjActionUpdate de PHPJabbers Cinema Booking System v2.0 permite a atacantes remotos escalar privilegios engañando a un administrador autenticado para que envíe una solicitud no autorizada.
First Time Phpjabbers cinema Booking System
Phpjabbers
References () https://github.com/ahrixia/CVE-2024-57429 - () https://github.com/ahrixia/CVE-2024-57429 - Exploit, Third Party Advisory
References () https://www.phpjabbers.com/cinema-booking-system/ - () https://www.phpjabbers.com/cinema-booking-system/ - Product
CPE cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*

06 Feb 2025, 22:15

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

06 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 17:15

Updated : 2025-06-24 00:13


NVD link : CVE-2024-57429

Mitre link : CVE-2024-57429

CVE.ORG link : CVE-2024-57429


JSON object : View

Products Affected

phpjabbers

  • cinema_booking_system
CWE
CWE-352

Cross-Site Request Forgery (CSRF)