Skip to content

Menu
  • Home
Menu

CVE-2025-41002 – SQL injection in Infoticketing

Posted on February 23, 2026
CVE ID : CVE-2025-41002

Published : Feb. 23, 2026, 10:16 a.m. | 30 minutes ago

Description : SQL injection vulnerability in Infoticketing. This vulnerability allows
an unauthenticated attacker to retrieve, create, update, and delete the
database by sending a POST request using the ‘code’ parameter in ‘/components/cart/cartApplyDiscount.php’.

Severity: 9.3 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

©2026 | Design: Newspaperly WordPress Theme