CyberRota Analysis
AI-GeneratedThe Travel Agency Management System by Win Men International is vulnerable to a critical SQL Injection flaw, allowing unauthenticated remote attackers to execute arbitrary SQL commands. This could lead to unauthorized access, modification, or deletion of sensitive database information. Organizations utilizing this system should prioritize immediate remediation to mitigate potential data breaches and integrity loss.
CVE
CVE-2026-19425
Severity
CRITICAL
CVSS
9.8
EPSS
0.47%
Original NVD Description
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.