CVE-2018-25167: Net-Billetterie Billetterie

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit malicious SQL code through the login POST parameter to extract database information including usernames, passwords, and system credentials.

Affected products

Published 2026-03-06. Last modified 2026-06-17.