Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026081310083434 | Publication Time | 2026-08-13 10:05:34 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-13 10:05:34 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Wei Ming International|Travel Agency Management System - SQL Injection |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000008 【Wei Ming International|Travel Agency Management System - SQL Injection】(CVE-2026-19425, CVSS: 9.8) The Travel Agency Management System developed by Wei Ming International contains an SQL Injection vulnerability. An unauthenticated remote attacker may inject arbitrary SQL commands to read, modify, and delete database contents. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
All versions of the Travel Agency Management System prior to the August 2026 security update |
|||
|
[Recommended Actions] August 2026 security update |
|||
|
[Reference] |
|||