A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
References
| Link | Resource |
|---|---|
| https://github.com/CH0ico/CVE_choco_7 | Exploit Mitigation Third Party Advisory |
| https://github.com/CH0ico/CVE_choco_7/blob/main/report.md | Exploit Mitigation Third Party Advisory |
| https://vuldb.com/?ctiid.349724 | Permissions Required VDB Entry |
| https://vuldb.com/?id.349724 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.767882 | Third Party Advisory VDB Entry |
| https://www.sourcecodester.com/ | Product |
Configurations
History
09 Mar 2026, 16:33
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References | () https://github.com/CH0ico/CVE_choco_7 - Exploit, Mitigation, Third Party Advisory | |
| References | () https://github.com/CH0ico/CVE_choco_7/blob/main/report.md - Exploit, Mitigation, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.349724 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.349724 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.767882 - Third Party Advisory, VDB Entry | |
| References | () https://www.sourcecodester.com/ - Product | |
| CPE | cpe:2.3:a:oretnom23:simple_responsive_tourism_website:1.0:*:*:*:*:*:*:* | |
| First Time |
Oretnom23 simple Responsive Tourism Website
Oretnom23 |
08 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-08 16:16
Updated : 2026-03-09 16:33
NVD link : CVE-2026-3746
Mitre link : CVE-2026-3746
CVE.ORG link : CVE-2026-3746
JSON object : View
Products Affected
oretnom23
- simple_responsive_tourism_website
