Cross-Site Scripting Flaw in Online Ticket Booking by a Leading Vendor
CVE-2018-5078

4.8MEDIUM

What is CVE-2018-5078?

The vulnerability in Online Ticket Booking allows an attacker to inject malicious scripts through the admin/eventlist.php cast parameter. This XSS flaw can lead to unauthorized access and manipulation of session information, potentially compromising user data and overall system integrity. Proper filtering and validation of input parameters are crucial to mitigate this risk.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.