חזרה ללוח
D47אומת בקודP0
SQL injection in `exit_ticket()`: `event_id`/`seat` interpolated unprepared into SELECT
B · unauth-POSTS3 · destructiveSECT1
תיקון
מורכבות low95%
A seat parameter is placed into a database query unsafely, allowing SQL injection.
Seater.php:212