Executive brief
Tourism-Management-System is an open-source tourism platform built with Spring Boot that manages bookings, reviews, and customer data. A SQL injection vulnerability in the Common Controller allows unauthenticated remote attackers to manipulate database queries by injecting malicious SQL through table and column parameters, potentially exposing or modifying sensitive tourism and customer data.
Technical details
A SQL injection vulnerability exists in the CommonController component (CommonDao) within travel/src/main/java/com/controller/CommonController.java. The vulnerability arises from insufficient input validation on the table, column, xColumn, and yColumn parameters, which are concatenated directly into SQL queries without parameterization. An unauthenticated attacker can exploit this via network access by crafting malicious requests with specially crafted parameter values. Successful exploitation allows attackers to extract, modify, or delete database records. A patch has been released (commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86) and should be applied immediately.
Affected products
- jaychouchannel Tourism-Management-System up to commit 8122bf020d91199eddfff3ee02d1632a70a9a132
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fix released in commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86