CVE-2026-86282: jaychouchannel Tourism-Management-System CommonDao CommonController.java sql injection
A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument table/column/xColumn/yColumn can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. This patch is called d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
jaychouchannel Tourism-Management-System CommonDao CommonController.javato a version that resolves this vulnerability.Patch d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86
Event History
Frequently Asked Questions
What inputs need to be controlled to exploit this issue?
An attacker needs to manipulate the table, column, xColumn, or yColumn argument handled by CommonController.java through the CommonDao component. The attack can be launched remotely and requires no stated privileges or user interaction.
How can I determine whether my deployment is affected?
Check whether the deployed source includes travel/src/main/java/com/controller/CommonController.java and whether it is based on code at or before commit 8122bf020d91199eddfff3ee02d1632a70a9a132. Because the product does not use versioning, affected and unaffected release versions are not available.
What remediation is available?
Apply patch commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. Public exploit availability means remediation should be prioritized.