Impact
The Simple Flight Ticket Booking System 1.0 is vulnerable in Adminsearch.php where the flightno argument is improperly processed, allowing an attacker to inject arbitrary SQL. The injection can be performed remotely and can compromise the confidentiality and integrity of the underlying database, potentially exposing sensitive booking information or allowing unauthorized data manipulation.
Affected Systems
The vulnerability affects code-projects Simple Flight Ticket Booking System version 1.0. No other versions or vendors are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless the remote nature of the attack and the lack of public fixes warrant attention.
OpenCVE Enrichment