CodeAstro Online Movie Ticket Booking System Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in CodeAstro Online Movie Ticket Booking System version 1.0. This vulnerability allows an attacker to trick an authenticated user into submitting crafted POST data, which can result in unauthorized actions such as searching records without the user's knowledge.

Impact

Exploitation of this vulnerability allows for cross-site request forgery, where an attacker can perform actions on behalf of an authenticated user without their consent.

Reproduction

To reproduce this vulnerability, an attacker must create a malicious link or form that, when clicked or submitted by an authenticated user, sends a request to the application that performs an action on behalf of the user. This can be done by exploiting the application's lack of proper CSRF protection on sensitive actions.

Added: Jul 7, 2025, 3:17 PM
Updated: Jul 7, 2025, 3:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.