CVE-2025-41002 – SQL injection in Infoticketing

CVE ID : CVE-2025-41002

Published : Feb. 23, 2026, 10:16 a.m. | 49 minutes ago

Description : SQL injection vulnerability in Infoticketing. This vulnerability allows
an unauthenticated attacker to retrieve, create, update, and delete the
database by sending a POST request using the ‘code’ parameter in ‘/components/cart/cartApplyDiscount.php’.

Severity: 9.3 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه