Skip to content
ביקורת אבטחה
חזרה ללוח
D47אומת בקודP0

SQL injection in `exit_ticket()`: `event_id`/`seat` interpolated unprepared into SELECT

B · unauth-POSTS3 · destructiveSECT1
תיקון
95%
מורכבות low

A seat parameter is placed into a database query unsafely, allowing SQL injection.

Seater.php:212