Posting Date: 2026/08/13
【Vulnerability Alert】VMING|Travel Agency Management System - SQL Injection
- Subject: 【Vulnerability Alert】VMING|Travel Agency Management System - SQL Injection
- Description:
- Forwarded Cybersecurity Alert from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202608-00000008
- 【VMING|Travel Agency Management System - SQL Injection】(CVE-2026-19425, CVSS: 9.8) A SQL Injection vulnerability exists in the Travel Agency Management System developed by VMING. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database contents.
- Affected Systems:
- All versions of Travel Agency Management System prior to the August 2026 security update
- Recommendations:
- August 2026 security update
- References:
Computer and Communication Center
Network System Division