:::

【Security Vulnerability Alert】Win Men International|Travel Agency Management System - SQL Injection

Type:行政公告
Pubish Date:2026/08/17 至 2027/02/17
Visitors:94

Forwarded from Taiwan Computer Emergency Response Team/Coordination Center Security Information Alert TWCERTCC-200-202608-00000008

[Description]
【Win Men International|Travel Agency Management System - SQL Injection】(CVE-2026-19425,CVSS:9.8) The Travel Agency Management System developed by Win Men International contains an SQL Injection vulnerability. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database contents.

[Affected Platforms]
All versions of the Travel Agency Management System prior to the August 2026 security update

[Recommended Measures]
August 2026 security update

[References]
1.https://www.twcert.org.tw/tw/cp-132-11098-0fb4a-1.html

相關附件

※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。

返回列表