CVE-2024-57429

MEDIUM

Phpjabbers Cinema Booking System - CSRF

Title source: rule
STIX 2.1

Description

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

Exploits (1)

nomisec WORKING POC
by ahrixia · poc
https://github.com/ahrixia/CVE-2024-57429

Scores

CVSS v3 5.4
EPSS 0.0086
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
phpjabbers/cinema_booking_system 2.0
Published Feb 06, 2025
Tracked Since Feb 18, 2026