CVE-2026-3746: SourceCodester Simple Responsive Tourism Website Login Login.php sql injection
A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3746?
The severity of CVE-2026-3746 is categorized as critical due to its potential for SQL injection attacks.
How do I fix CVE-2026-3746?
To fix CVE-2026-3746, sanitize and validate user inputs in the affected Login.php file to prevent SQL injection.
What components are affected by CVE-2026-3746?
CVE-2026-3746 affects the Login component of the SourceCodester Simple Responsive Tourism Website.
What is the impact of CVE-2026-3746?
The impact of CVE-2026-3746 allows attackers to execute arbitrary SQL commands in the database, compromising sensitive data.
Is there a patch available for CVE-2026-3746?
Currently, there is no specific patch available for CVE-2026-3746; implementing input validation is recommended to mitigate the risk.