go to Center block
Upper block

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Win Men Intermational|Travel Agency Management System - SQL Injection

TVN ID TVN-202607009
CVE ID CVE-2026-19425
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Travel Agency Management System versions prior to the August 2026 Security Update
Description Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
Solution Upgrade to August 2026 Security Update or later.
Credit mlgzackfly(cymetrics)
Public Date 2026-08-11
Top