Impact
Based on the description, it is inferred that an unauthenticated SQL injection flaw exists in the SearchResultOneway.php file of the code‑projects Simple Flight Ticket Booking System 1.0. The vulnerability is triggered by manipulating a request argument, allowing an attacker to inject arbitrary SQL commands. This could lead to unauthorized data disclosure, tampering, or even full database compromise. The weakness is categorized as CWE‑74 and CWE‑89.
Affected Systems
The affected product is code‑projects Simple Flight Ticket Booking System version 1.0, as indicated by the vendor/product name and accompanying CPE string.
Risk and Exploitability
The flaw has a CVSS score of 6.9, indicating functional impact with the potential for significant data loss. The EPSS score is below 1%, suggesting low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely from any Internet‑connected host that can access the application. The description does not mention authentication prerequisites, so it is inferred that an attacker can exploit it freely by crafting a request to the vulnerable endpoint.
OpenCVE Enrichment