PHPJabbers Cinema Booking System
cpe:2.3:a:phpjabbers:cinema_booking_system:*:*:*:*:*:*:*
- 2.0
A stored cross-site scripting vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0. This vulnerability arises from unsanitized input in file upload fields, specifically 'event_img' and 'seat_maps', as well as in seat number configurations. Attackers can exploit this flaw to inject persistent JavaScript, which could be used for phishing, malware injection, or session hijacking.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected JavaScript is executed in the context of the user, potentially leading to session theft, phishing attacks, or malware distribution.
To reproduce this vulnerability, upload a file through the 'event_img' field that includes a crafted image filename containing JavaScript payloads, such as an image file named 'luffy.jpg' with an embedded script. Alternatively, during the seat number configuration, inject a script payload into the seat number fields, which will be executed when the data is accessed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.