CVE-2025-41002: Manantial De Ideas Infoticketing

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code' parameter in '/components/cart/cartApplyDiscount.php'.

Affected products

Published 2026-02-23. Last modified 2026-06-17.