Sceawere
Vulnerability Detail
CVE-2026-105889UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tickera Blind SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 3h ago
- Vendor
- Tickera
- Product
- Tickera
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-10T17:17:00.063Z",
"pubdate": "2026-10-10T17:17:00.063Z",
"executiveSummary": "This vulnerability is classified as an Improper Neutralization of Special Elements used in an SQL Command, commonly referred to as SQL Injection (CWE-89).\nThe vulnerability specifically facilitates Blind SQL Injection attacks, enabling an unauthenticated or authenticated attacker to infer database contents by observing application responses to specially crafted SQL queries.\nThe affected product is the Tickera Event Ticketing System, impacting versions from n/a through 3.6.0.6.\nThe risk implication is critical, as it may lead to unauthorized disclosure of sensitive data, such as administrative credentials, customer information, or configuration details stored within the underlying database.\nThe attacker requires no specific prior knowledge beyond the ability to interact with the target system's input parameters. Successful exploitation necessitates the ability to manipulate HTTP requests that communicate with the vulnerable database backend, allowing for the iterative extraction of data via boolean or time-based inference techniques.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization and parameterized handling of user-supplied input before it is concatenated into SQL statements within the Tickera plugin components.\nBlind SQL Injection occurs when the application is vulnerable to SQL injection but does not return the direct results of the query in the HTTP response. Instead, the attacker leverages the application's behavioral differences—such as changes in content, HTTP status codes, or response latency—to determine whether a logical condition injected into the query evaluates to true or false.\nThe attack flow begins with the identification of an entry point where user input is processed by the Tickera plugin without adequate escaping. An attacker crafts a malicious payload containing SQL logic, such as 'AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)--'. By injecting this into a parameter, the attacker observes if the server-side response delay corresponds to the sleep duration, confirming the vulnerability.\nOnce the vulnerability is confirmed, the attacker utilizes boolean-based or time-based inference to perform binary searches on database metadata. This involves iterating through each character of a target string (e.g., table names, column names, or user passwords) by testing conditions such as 'AND (SELECT SUBSTRING(password,1,1) FROM users WHERE username='admin')='a''.\nThis iterative process allows the attacker to reconstruct the entire database schema and contents systematically. The vulnerable component operates by passing unvalidated parameters directly to database abstraction layers that fail to enforce strict type checking or query parameterization.\nThe impact is significant, as the attacker can perform data exfiltration, bypass authentication mechanisms, or escalate privileges within the WordPress environment. Because the database interaction is server-side, the attacker's requests are executed with the permissions of the database user configured for the CMS, which typically holds broad access to the tables.\nThe vulnerability is present in versions up to and including 3.6.0.6. Successful exploitation is generally performed over a network interface and does not require elevated administrative privileges if the input parameter is exposed on the public-facing side of the ticketing system."
}