Impact
A vulnerability exists in the login.php component of code‑projects Concert Ticket Reservation System 1.0, allowing attackers to inject arbitrary SQL through the Email parameter. This SQL injection can lead to unauthorized access to, modification of, or destruction of database contents. The flaw may be exploited remotely, giving attackers potential to compromise application data integrity and confidentiality.
Affected Systems
The affected product is code‑projects Concert Ticket Reservation System version 1.0. The vulnerability resides in the login.php file within the Parameter Handler component, and can affect all installations of the 1.0 release that have not applied any mitigation.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Exploitation is possible without authentication over the web interface, and the vulnerability has publicly available exploits. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog. Attackers can craft malicious Email inputs to hijack database queries remotely. The lack of mitigation allows for potential data breaches and database corruption if not addressed promptly.
OpenCVE Enrichment