A critical unauthenticated SQL injection flaw in the fgtapi.frontgatetickets.com API allowed full administrative takeover of Front Gate Tickets, a Live Nation/Ticketmaster subsidiary that supports major U.S. festivals and events. Researcher Ian Carroll found that device-management endpoints accepted an unsanitized deviceUID parameter through unauthenticated middleware used by scanner and box-office hardware, creating a path to the backend database despite AWS WAF protections. Standard tooling reportedly failed, but a nested-payload bypass enabled a boolean-based blind SQL injection technique that exposed live reset tokens and API credentials and ultimately allowed the hijacking of an administrator account without the password.
With administrator access, an attacker could have manipulated ticket inventory and pricing, issued unlimited complimentary tickets, and accessed customer and staff account data across the platform. The reporting says the flaw was remediated quickly after disclosure, but the incident underscored the risk posed by legacy, internet-facing ticketing infrastructure and showed how AI assistance was used to refine exploitation against protected endpoints when conventional methods were ineffective.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Front Gate Tickets reportedly fixed the vulnerability shortly after it was identified. The remediation closed a path that could have allowed attackers to manipulate inventory and pricing, issue complimentary tickets, and access customer and staff account data.
After standard tooling was ineffective against AWS WAF protections, the researcher used Anthropic's Claude Opus to help identify a nested-payload bypass and build a boolean-based blind SQL injection method. Using the flaw, he accessed the database, read live reset and API tokens, and hijacked an administrator account without the password.
Ian Carroll found a critical unauthenticated SQL injection vulnerability in the fgtapi.frontgatetickets.com API used by Front Gate Tickets, a Live Nation/Ticketmaster subsidiary. The flaw enabled full administrative takeover of the ticketing platform through device-related endpoints that accepted an unsanitized deviceUID parameter.
A report analyzing an exposed repository tied to a Chinese-linked mass WordPress/CMS exploitation operation identified 5,279 unique government or public-sector domains across 26,491 appearances. It found that while most domains appeared in raw target lists, some also appeared in validation outputs, shell inventories, and execution-log-like artifacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.