CVE-2018-25167: Net-Billetterie Billetterie
High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit malicious SQL code through the login POST parameter to extract database information including usernames, passwords, and system credentials.
Affected products
- Net-Billetterie Billetterie: version 2.9 only
Published 2026-03-06. Last modified 2026-06-17.