Cross-Site Scripting Vulnerability in Online Ticket Booking by D4wner
CVE-2018-5075
4.8MEDIUM
Key Information:
- Vendor
- CVE Published:
- 3 January 2018
What is CVE-2018-5075?
The Online Ticket Booking application is susceptible to a Cross-Site Scripting (XSS) vulnerability via the 'snacks_name' parameter in admin/snacks_edit.php. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to the theft of sensitive information and session cookies.
