Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

Simple Flight Ticket Booking System Login SQL Injection Risk

CVE-2026-3708
Summary

An attacker could inject malicious code into the Simple Flight Ticket Booking System's login feature, potentially allowing them to access user accounts. This means that hackers may be able to steal sensitive information or take control of user accounts. We recommend updating to a patched version of the system or implementing security patches to prevent this type of attack.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
carmelo simple_flight_ticket_booking_system 1.0 –
Original title
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the ar...
Original description
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
nvd CVSS2.0 7.5
nvd CVSS3.1 7.3
nvd CVSS4.0 6.9
Vulnerability type
CWE-74 Injection
CWE-89 SQL Injection
Published: 8 Mar 2026 · Updated: 13 Mar 2026 · First seen: 8 Mar 2026