{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aphpjabberscinema_booking_system2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.4,"id":"CVE-2024-57429"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cinema Booking System (2.0)"],"_cs_severities":["low"],"_cs_tags":["web-vulnerability","csrf","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["PHPJabbers"],"content_html":"\u003cp\u003eCVE-2024-57429 is a CSRF vulnerability identified in the PHPJabbers Cinema Booking System v2.0. The flaw exists within the 'pjActionUpdate' function, which fails to properly validate the authenticity of requests. An attacker can craft a malicious web page containing a hidden form that triggers an automated POST request to the application's administrative update endpoint. By tricking an authenticated administrator into visiting the attacker-controlled page, the victim's browser initiates the request under their active session. This allows the attacker to modify user attributes, including account roles and passwords, resulting in unauthorized privilege escalation or full account takeover of administrative profiles. Because the application lacks sufficient anti-CSRF protections on this sensitive function, it remains highly vulnerable to social engineering-based exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to escalate privileges to administrative level. This leads to complete administrative account takeover, including the ability to change passwords, modify user permissions, and potentially disrupt or compromise the booking platform. The vulnerability poses a medium risk due to the requirement for user interaction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the implementation of anti-CSRF tokens for all state-changing operations within the PHPJabbers Cinema Booking System application. Until a vendor-supplied patch is available, instruct administrative users to avoid clicking unknown links while logged into the application dashboard. Implement strict Referer and Origin header validation on the 'pjActionUpdate' endpoint to verify that requests originate from legitimate platform pages.\u003c/p\u003e\n","date_modified":"2026-09-01T05:10:55Z","date_published":"2026-09-01T05:10:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-57429/","summary":"CVE-2024-57429 is a Cross-Site Request Forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0, allowing attackers to perform administrative account takeover via malicious web requests.","title":"CSRF Vulnerability in PHPJabbers Cinema Booking System","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-57429/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:phpjabbers:cinema_booking_system:2.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}