【Vulnerability Alert】Wei Ming International|Travel Agency Management System - SQL Injection

publish date : 2026-08-21 update date : 2026-08-21

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026081310083434 Publication Time 2026-08-13 10:05:34
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-13 10:05:34
Impact Level Low  
[Subject]
【Vulnerability Alert】Wei Ming International|Travel Agency Management System - SQL Injection
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000008

【Wei Ming International|Travel Agency Management System - SQL Injection】(CVE-2026-19425, CVSS: 9.8) The Travel Agency Management System developed by Wei Ming International contains an SQL Injection vulnerability. An unauthenticated remote attacker may inject arbitrary SQL commands to read, modify, and delete database contents.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

All versions of the Travel Agency Management System prior to the August 2026 security update

[Recommended Actions]

August 2026 security update

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center