CVE-2024-57427 Details
Description
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.
A reflected cross-site scripting vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0. This issue arises because multiple endpoints fail to properly sanitize user input, allowing the execution of malicious scripts in the context of the user's browser. Attackers can exploit this vulnerability by crafting harmful links that, when clicked, could steal session cookies or facilitate phishing attempts.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ahrixia/CVE-2024-57427 | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/ahrixia/CVE-2024-57427 | [email protected] | ExploitThird Party Advisory |
| https://www.phpjabbers.com/cinema-booking-system/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| phpjabbers cinema booking system | 2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2025 | Initial Analysis | [email protected] |
| Feb 6, 2025 | New CVE Received | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |