Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

Simple Flight Ticket Booking System 1.0 allows attackers to access unauthorized data

CVE-2026-3735
Summary

A critical flaw in the Simple Flight Ticket Booking System 1.0 allows attackers to access sensitive information by manipulating certain inputs. This can happen remotely, and since the exploit has been made public, it's essential to address this issue as soon as possible to prevent potential data breaches. Update the system to the latest version or patch the vulnerable file SearchResultOneway.php to ensure the security of your system.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
carmelo simple_flight_ticket_booking_system 1.0 –
Original title
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipula...
Original description
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
nvd CVSS3.1 7.3
nvd CVSS2.0 7.5
nvd CVSS4.0 6.9
Vulnerability type
CWE-74 Injection
CWE-89 SQL Injection
Published: 8 Mar 2026 · Updated: 13 Mar 2026 · First seen: 8 Mar 2026