CVE-2024-57428 Details
Description
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.
A stored cross-site scripting vulnerability has been identified in PHPJabbers Cinema Booking System version 2.0. This vulnerability arises from unsanitized input in file upload fields, specifically 'event_img' and 'seat_maps', as well as in seat number configurations. Attackers can exploit this flaw to inject persistent JavaScript, which could be used for phishing, malware injection, or session hijacking.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ahrixia/CVE-2024-57428 | [email protected] | ExploitThird Party Advisory |
| https://www.phpjabbers.com/cinema-booking-system/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| phpjabbers cinema booking system | 2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2025 | Initial Analysis | [email protected] |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Feb 6, 2025 | New CVE Received | [email protected] |