PT-2026-21246 · Sourcecodester · Simple Responsive Tourism Website

Anxxc

+3

·

Published

2026-02-20

·

Updated

2026-02-20

·

CVE-2026-2848

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-2848

Affected Products

Simple Responsive Tourism Website