CVE-2026-3711: code-projects Simple Flight Ticket Booking System Adminupdate.php sql injection
A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3711?
CVE-2026-3711 has been classified as a medium severity SQL injection vulnerability.
How does CVE-2026-3711 impact the Simple Flight Ticket Booking System?
CVE-2026-3711 allows attackers to manipulate SQL queries through the Adminupdate.php file, potentially exposing sensitive data.
How can I fix CVE-2026-3711?
To fix CVE-2026-3711, validate and sanitize user inputs in the affected parameters to prevent SQL injection.
Is CVE-2026-3711 an authorized access issue?
No, CVE-2026-3711 specifically pertains to SQL injection vulnerabilities and does not directly involve unauthorized access.
Which versions of the Simple Flight Ticket Booking System are affected by CVE-2026-3711?
CVE-2026-3711 affects version 1.0 of the Simple Flight Ticket Booking System.