Executive brief
A security vulnerability has been identified in the SourceCodester Ship Ferry Ticket Reservation System, a software platform used for managing ferry bookings. An attacker can exploit the login page to bypass security measures and gain unauthorized access to the administrative interface. This could allow an unauthorized individual to view customer data, modify ticket reservations, or disrupt the system's operations.
Technical details
A SQL injection vulnerability exists in SourceCodester Ship Ferry Ticket Reservation System up to version 1.0. The flaw is located in the '/admin/login.php' file within the Admin Login component. By manipulating the 'Username' input parameter, a remote, unauthenticated attacker can execute arbitrary SQL commands against the backend database. This vulnerability can be leveraged to bypass authentication mechanisms and gain full administrative access to the application. An exploit for this vulnerability has been disclosed publicly.
Affected products
- SourceCodester Ship Ferry Ticket Reservation System 1.0
Timeline
- 2026-06-05: disclosed: Public disclosure of the vulnerability and exploit details.