CVE-2023-44164: Projectworlds Online Movie Ticket Booking System

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

Affected products

  • Projectworlds Online Movie Ticket Booking System: version 1.0 only

Published 2023-09-28. Last modified 2026-06-17.