Junglewise Threat Intelligence

CVE-2026-19425: Win Men Intermational Travel Agency Management System SQL injection

CVE-2026-19425 · Severity: critical · CVSS 9.8 · Published 2026-08-11

Executive brief

Win Men Intermational's Travel Agency Management System contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary database commands remotely. Attackers can read, modify, or delete sensitive data stored in the system, potentially exposing customer information, bookings, and payment details, or disrupting business operations.

Technical details

The Travel Agency Management System contains a classic SQL injection vulnerability accessible to unauthenticated remote attackers. The vulnerability exists in input handling that fails to properly sanitize or parameterize SQL queries, allowing attackers to inject arbitrary SQL commands. With no authentication required and network reachability, an attacker can execute read, write, and delete operations against the backend database, potentially exposing customer records, payment information, and booking data. The vendor has released an August 2026 Security Update that should be applied immediately.

Affected products

  • Win Men Intermational Travel Agency Management System prior to August 2026 Security Update

Timeline

  • 2026-08-11: disclosed
  • 2026-08: patched: August 2026 Security Update released

References