CVE-2024-57427

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 6, 2025
CWE ID 79

Summary

CVE-2024-57427 is a reflected cross-site scripting (XSS) vulnerability affecting PHPJabbers Cinema Booking System version 2.0. The issue stems from multiple endpoints that fail to adequately sanitize user input. This flaw enables attackers to inject and execute malicious scripts in a victim's browser. The potential consequences include the theft of session cookies or the conduction of phishing attacks through crafted malicious links.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share