PHPJabbers Cinema Booking System SQL Injection Vulnerability in User Management Function

Vulnerability

A SQL injection vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0, specifically within the 'pjActionGetUser' function. This vulnerability allows attackers to manipulate database queries by exploiting the 'column' parameter. Successful exploitation could result in unauthorized access to sensitive information, privilege escalation, or manipulation of the database.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive data, unauthorized data modification, and potentially allow an attacker to escalate privileges within the application.

Reproduction

The vulnerability can be reproduced by sending a GET request to 'index.php' with the 'controller' set to 'pjAdminUsers', the 'action' set to 'pjActionGetUser', and the 'column' parameter manipulated to inject SQL payloads. This request can be made using a tool like SQLMap to automate the exploitation process.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
5.0
exploitability
9.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.