CVE-2024-57429
MEDIUMPHPJabbers Cinema Booking System 2.0 - Cross-Site Request Forgery in pjActionUpdate
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-57429. PoCs published by ahrixia.
AI-analyzed exploit summary This repository contains a functional CSRF PoC for CVE-2024-57429, targeting PHPJabbers Cinema Booking System v2.0. The exploit demonstrates privilege escalation by tricking an admin into submitting a malicious request that updates user details.
Description
A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.
Exploits (1)
This repository contains a functional CSRF PoC for CVE-2024-57429, targeting PHPJabbers Cinema Booking System v2.0. The exploit demonstrates privilege escalation by tricking an admin into submitting a malicious request that updates user details.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N