Cross-Site Scripting Vulnerability in Online Ticket Booking Software by an Unknown Vendor
CVE-2018-5072
4.8MEDIUM
Key Information:
- Vendor
- CVE Published:
- 3 January 2018
What is CVE-2018-5072?
The Online Ticket Booking software has a Cross-Site Scripting (XSS) vulnerability that can be exploited via the 'keyword' parameter in the admin/sitesettings.php file. This flaw may allow attackers to inject malicious scripts, potentially leading to unauthorized actions performed on behalf of users when they interact with the compromised application.
