Description
A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-03-07: | Advisory disclosed |
| 2026-03-07: | VulDB entry created |
| 2026-03-07: | VulDB entry last update |
Credits
Choco094late (VulDB User)
References
vuldb.com/?id.349724 (VDB-349724 | SourceCodester Simple Responsive Tourism Website Login Login.php sql injection)
vuldb.com/?ctiid.349724 (VDB-349724 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.767882 (Submit #767882 | sourcecodester.com Simple Responsive Tourism Website V1.0 SQL Injection)
github.com/CH0ico/CVE_choco_7
github.com/CH0ico/CVE_choco_7/blob/main/report.md
www.sourcecodester.com/