CVE-2026-2848: SourceCodester Simple Responsive Tourism Website Registration Master.php sql injection
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2848?
CVE-2026-2848 has a high severity rating due to the potential for SQL injection attacks.
How do I fix CVE-2026-2848?
To fix CVE-2026-2848, you should sanitize and validate all user inputs in the registration functionality.
What component is affected by CVE-2026-2848?
CVE-2026-2848 affects the registration functionality in the /classes/Master.php file of SourceCodester Simple Responsive Tourism Website 1.0.
What type of vulnerability is CVE-2026-2848?
CVE-2026-2848 is classified as an SQL injection vulnerability.
What might an attacker gain from exploiting CVE-2026-2848?
An attacker exploiting CVE-2026-2848 could gain unauthorized access to the database and potentially compromise sensitive data.