Description
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Published: 2026-03-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection enabling remote data exfiltration or modification
Action: Apply Patch
AI Analysis

Impact

The Simple Flight Ticket Booking System 1.0 is vulnerable in Adminsearch.php where the flightno argument is improperly processed, allowing an attacker to inject arbitrary SQL. The injection can be performed remotely and can compromise the confidentiality and integrity of the underlying database, potentially exposing sensitive booking information or allowing unauthorized data manipulation.

Affected Systems

The vulnerability affects code-projects Simple Flight Ticket Booking System version 1.0. No other versions or vendors are listed as affected.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless the remote nature of the attack and the lack of public fixes warrant attention.

Generated by OpenCVE AI on April 16, 2026 at 10:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for an official update or patch from code-projects and apply it immediately.
  • If no patch is available, refactor the flightno handling to use parameterized queries or proper input sanitization to eliminate the injection vector.
  • Restrict access to the /Adminsearch.php endpoint to authenticated administrators only, and consider blocking remote access from untrusted networks.

Generated by OpenCVE AI on April 16, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Carmelo
Carmelo simple Flight Ticket Booking System
CPEs cpe:2.3:a:carmelo:simple_flight_ticket_booking_system:1.0:*:*:*:*:*:*:*
Vendors & Products Carmelo
Carmelo simple Flight Ticket Booking System

Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects simple Flight Ticket Booking System
Vendors & Products Code-projects
Code-projects simple Flight Ticket Booking System

Sun, 08 Mar 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Title code-projects Simple Flight Ticket Booking System Adminsearch.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Carmelo Simple Flight Ticket Booking System
Code-projects Simple Flight Ticket Booking System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-10T14:02:33.541Z

Reserved: 2026-03-07T08:58:20.273Z

Link: CVE-2026-3705

cve-icon Vulnrichment

Updated: 2026-03-10T14:02:27.505Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-08T05:16:29.313

Modified: 2026-03-09T16:18:56.983

Link: CVE-2026-3705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T10:45:26Z

Weaknesses