SQL Injection Vulnerability in Travel Agency Management System by Win Men International
CVE-2026-19425

9.3CRITICAL

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-19425?

The Travel Agency Management System developed by Win Men International is susceptible to an SQL Injection vulnerability. This flaw allows unauthenticated remote attackers to execute arbitrary SQL commands. By exploiting this vulnerability, an attacker can read, modify, or delete sensitive data stored in the database, potentially compromising the integrity and confidentiality of the system. Organizations using this software are advised to assess their security measures and implement necessary updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Travel Agency Management System all

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.