【Vulnerability Alert】Wei Ming International|Travel Agency Management System - SQL Injection
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026081310083434 | Publication Time | 2026-08-13 10:05:34 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-13 10:05:34 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Wei Ming International|Travel Agency Management System - SQL Injection |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000008 【Wei Ming International|Travel Agency Management System - SQL Injection】(CVE-2026-19425, CVSS: 9.8) The Travel Agency Management System developed by Wei Ming International contains an SQL Injection vulnerability. An unauthenticated remote attacker may inject arbitrary SQL commands to read, modify, and delete database contents. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
All versions of the Travel Agency Management System prior to the August 2026 security update |
|||
|
[Recommended Actions] August 2026 security update |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





