Executive brief
The Nur-Alam39 bus-ticket application, an online bus reservation system, contains a critical security flaw that allows unauthorized users to access its database. By sending a specially crafted request, an attacker can bypass security controls to view sensitive information or potentially take control of the entire database. This could lead to the exposure of customer data, booking details, and administrative credentials.
Technical details
An unauthenticated SQL injection vulnerability exists in bus_info.php of the Nur-Alam39 bus-ticket project. The 'busid' parameter received via HTTP POST is directly concatenated into a MySQL query string without any sanitization or parameterization. Because the application connects to the database using the MySQL 'root' account with an empty password, a remote attacker can use UNION-based payloads to extract arbitrary data from the 'bus_service' database or other accessible databases. The vulnerability is present in the latest commit (459cabd) and no patched version is currently available.
Affected products
- Nur-Alam39 bus-ticket latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad
Timeline
- 2026-06-18: disclosed: Vulnerability published via NVD and TuranSec