SQL Injection Flaw in Online Movie Ticket Booking System by Project World
CVE-2021-44866
7.5HIGH
What is CVE-2021-44866?
A vulnerability has been identified within the Online-Movie-Ticket-Booking-System 1.0 that allows for SQL injection due to inadequate input validation on the 'id' parameter in the about.php file. Attackers can exploit this flaw by appending malicious SQL queries, leading to unauthorized access to sensitive database information.