Eventobot SQL Injection Vulnerability Allowing Database Manipulation

Vulnerability

A SQL injection vulnerability has been identified in Eventobot, a platform for event management and ticket sales. This vulnerability allows attackers to retrieve, create, update, and delete databases by exploiting the 'promo_send' parameter in the '/assets/php/calculate_discount.php' file.

Impact

Exploitation of this vulnerability allows for unauthorized database access and manipulation, including the ability to read, create, update, and delete database records.

Remediation

The Eventobot team has fixed this vulnerability in the latest version.

Added: Mar 9, 2026, 10:18 AM
Updated: Mar 9, 2026, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.6
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.