PT-2026-23941 · Unknown · Simple Flight Ticket Booking System
Xuyue
·
Publicado
2026-03-08
·
Atualizado
2026-03-13
·
CVE-2026-3736
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simple Flight Ticket Booking System version 1.0
Description
A flaw exists in Simple Flight Ticket Booking System version 1.0, specifically within the SearchResultRoundtrip.php file. Manipulation of input provided to the application through the
results argument can lead to SQL injection. This issue can be exploited remotely. The exploit for this issue has been publicly released.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Simple Flight Ticket Booking System