Cross-Site Scripting Vulnerability in Online Ticket Booking by Unknown Vendor
CVE-2018-5074

4.8MEDIUM

What is CVE-2018-5074?

An XSS vulnerability in the Online Ticket Booking system allows attackers to exploit the admin/manageownerlist.php contact parameter, potentially enabling them to execute arbitrary scripts in the context of an authenticated administrator session. This could lead to unauthorized actions being performed on behalf of the admin, compromising the security of the entire application and its users.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.