
Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter
[Vulnerability Type] SQL Injection
Description A Time-Based Blind SQL Injection vulnerability was discovered in Ticket-Booking-App - 1.0 that allows an attacker to execute arbitrary SQL queries on the underlying database. The vulnerable parameter does not properly sanitize user-supplied input, allowing the injection of malicious SQL payloads that rely on time delays to infer the presence of a vulnerability. Unlike classical SQL injection, time-based blind SQL injection does not return data directly. Instead, the attacker determines if the injection was successful based on the time the application takes to respond.
[Vendor of Product] Code-project
[Affected Product Code Base] Ticket-Booking-App - 1.0
[Affected Component] Email Parameter is vulnerable to Time Based SQL Injection
[Attack Type] Remote
[Impact Code execution] true
[Impact Information Disclosure] true
[CVE Impact Other] Time Based SQLI
[Attack Vectors]
Vulnerable Endpoint: Navigate to the following endpoint in the application: Ticket-Booking-App/authenticate.php
Injection Point: In the application's login form or API request, inject the following payload into the email parameter:
%2b(select*from(select(sleep(20)))a)%2b
(This is the URL-encoded form of: +(select * from (select(sleep(20)))a)+)
Impact Successful exploitation of this vulnerability allows a remote unauthenticated attacker to: Confirm the presence of a SQL injection flaw Enumerate the database structure Extract sensitive information from the backend DBMS Perform unauthorized operations depending on the DBMS user privileges This type of vulnerability is particularly dangerous as it can be exploited without any visible output or error messages from the application.
[Reference] https://code-projects.org/ticket-booking-in-php-with-source-code/
[Discoverer] Shubham Ghadge
Use CVE-2025-28346.