CVE-2026-3735: code-projects Simple Flight Ticket Booking System SearchResultOneway.php sql injection
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3735?
CVE-2026-3735 is considered a high severity SQL injection vulnerability that can potentially allow attackers to manipulate database queries.
How do I fix CVE-2026-3735?
To fix CVE-2026-3735, sanitize and validate all user inputs in the SearchResultOneway.php file to prevent SQL injection attacks.
What systems are affected by CVE-2026-3735?
CVE-2026-3735 affects Code-projects Simple Flight Ticket Booking System 1.0 due to a vulnerability in its SearchResultOneway.php functionality.
What type of vulnerability is CVE-2026-3735?
CVE-2026-3735 is classified as an SQL injection vulnerability, allowing unauthorized database access.
Can CVE-2026-3735 lead to data exposure?
Yes, if exploited, CVE-2026-3735 can lead to unauthorized access and potential exposure of sensitive data stored in the database.