SQL Injection Vulnerability in Tickera Event Ticketing System by Tickera
CVE-2026-105889
9.3CRITICAL
What is CVE-2026-105889?
The Tickera Event Ticketing System is vulnerable to a SQL Injection attack due to improper neutralization of special elements in SQL commands. This vulnerability allows an attacker to perform blind SQL injection, which could potentially lead to unauthorized data access or manipulation. It affects all versions from n/a up to and including 3.6.0.6, making it imperative for users to apply the necessary patches and updates to secure their systems.
Affected Version(s)
Tickera 0 <= 3.6.0.6
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rasyid Abdi Gantoro | Patchstack Bug Bounty Program