{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-86282/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86282"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Tourism-Management-System (commits up to 8122bf020d91199eddfff3ee02d1632a70a9a132)"],"_cs_severities":["high"],"_cs_tags":["web-application","sql-injection","cve-2026-86282"],"_cs_type":"advisory","_cs_vendors":["jaychouchannel"],"content_html":"\u003cp\u003eA SQL injection vulnerability exists in the Tourism-Management-System repository maintained by jaychouchannel. The flaw resides within the CommonDao component, specifically inside the 'travel/src/main/java/com/controller/CommonController.java' file. An attacker can exploit this remotely by injecting malicious input into the 'table', 'column', 'xColumn', or 'yColumn' parameters. Because the application fails to properly sanitize these inputs before including them in SQL queries, an attacker can bypass authentication, exfiltrate sensitive data, or modify database contents.\u003c/p\u003e\n\u003cp\u003ePublicly available exploit code has been released, increasing the risk of exploitation. As the project does not utilize standard versioning, all instances running commits up to 8122bf020d91199eddfff3ee02d1632a70a9a132 are considered vulnerable. Security teams should prioritize patching the system using the official fix provided in commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to perform SQL injection attacks. This can result in unauthorized access to sensitive application data, potential modification or deletion of records, and under certain configurations, escalation of privileges or administrative takeover of the backend database. All organizations hosting this system are at risk of data breaches and service disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patch provided in commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86 to all instances of the Tourism-Management-System.\u003c/li\u003e\n\u003cli\u003eAudit access logs for abnormal HTTP requests containing SQL keywords (e.g., SELECT, UNION, SLEEP) targeting the CommonController endpoint.\u003c/li\u003e\n\u003cli\u003eEnforce strict input validation on all parameters handled by CommonController.java.\u003c/li\u003e\n\u003cli\u003eMonitor webserver traffic for incoming requests where the query parameters 'table', 'column', 'xColumn', or 'yColumn' contain suspicious SQL syntax or metacharacters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T08:51:39Z","date_published":"2026-09-07T08:51:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tourism-management-sql-injection/","summary":"The Tourism-Management-System contains a critical SQL injection vulnerability in the CommonDao component allowing remote unauthenticated attackers to execute arbitrary database queries.","title":"SQL Injection Vulnerability in Tourism-Management-System","url":"https://feed.craftedsignal.io/briefs/2026-09-tourism-management-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-86282","version":"https://jsonfeed.org/version/1.1"}