CVE-2026-86282
Received Received - Intake

SQL Injection in Tourism Management System

Vulnerability report for CVE-2026-86282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: VulDB

Description

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument table/column/xColumn/yColumn can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. This patch is called d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. A patch should be applied to remediate this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jaychouchannel tourism_management_system to 8122bf020d91199eddfff3ee02d1632a70a9a132 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an SQL injection flaw in the Tourism-Management-System project. It exists in the CommonController.java file where user-provided inputs for table, column, xColumn, and yColumn parameters are directly used in SQL queries without proper validation. An attacker can manipulate these inputs to inject malicious SQL code, potentially accessing or modifying database contents remotely.

Detection Guidance

To detect SQL injection vulnerabilities in the Tourism-Management-System, inspect the CommonController.java file for unsanitized user inputs in table/column parameters. Check if SqlIdentifierValidator.java exists and validates inputs. Review endpoints handling /option and password reset paths for proper authentication. Use static code analysis tools like SonarQube or Checkmarx to scan for SQL injection patterns.

Impact Analysis

If you are using this system, an attacker could exploit this to read, alter, or delete sensitive data in your database. They might steal user credentials, modify travel bookings, or disrupt system operations. The public availability of exploit code increases the risk of real-world attacks.

Compliance Impact

This vulnerability likely violates GDPR's data protection requirements by enabling unauthorized access to personal data. For HIPAA, it could compromise protected health information if the system handles such data. Both standards require strict access controls and protection against data breaches, which this flaw undermines.

Mitigation Strategies

Apply the patch commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86 to add SqlIdentifierValidator and sanitize inputs. Update CommonController.java and related controllers to validate table/column names. Remove @IgnoreAuth from password reset endpoints and enforce session checks. Restrict sensitive column access via /option endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86282. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart