← Terug naar overzicht

A SQL injection vulnerability has been identified in jaychouchannel's Tourism-Management-System up to commit 8122bf020d91199eddfff3ee02d1632a70a9a132. The vulnerability resides in the file travel/src/main/java/com/controller/CommonController.java within the CommonDao component. Attackers can manipulate the table, column, xColumn, and yColumn arguments to execute SQL injection attacks remotely. The exploit has been publicly disclosed, increasing the risk of active exploitation. The product does not use versioning, making it difficult to identify affected and unaffected releases. A patch (commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86) has been made available and should be applied immediately. The vulnerability was reported via GitHub issues and pull requests and tracked on VulDB as well as NVD.

Affected products

  • jaychouchannel Tourism-Management-System

Related CVE's

  • CVE-2026-86282

Categories

  • Database & Storage
  • Web Technologies