PoC Index

CVE-2024-57429

MEDIUM 5.4EPSS 0.3%

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS
0.28% chance of exploitation in the next 30 days, 20th percentile
Published
2025-02-06

Proof-of-concept exploits (1)

References

Related