📦

online_movie_ticket_booking_system

Vendor: projectworlds

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 0.62% Exploit Prob.
Latest CVE CVE-2025-7133 Jul 07

Security Vulnerability Index

Page 1 / 1
2.1 CVSS

A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

EPSS: 0.22%
6.4 CVSS

Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.

EPSS: 0.35%
9.8 CVSS

The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.

EPSS: 0.81%
9.8 CVSS

The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

EPSS: 0.81%
9.8 CVSS

The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.

EPSS: 0.81%
5.4 CVSS

Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.

EPSS: 0.34%
7.5 CVSS

An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

EPSS: 1.00%