Posting Date: 2026/08/13

【Vulnerability Alert】VMING|Travel Agency Management System - SQL Injection

  • Subject: 【Vulnerability Alert】VMING|Travel Agency Management System - SQL Injection


  • Description:
    • Forwarded Cybersecurity Alert from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202608-00000008
    • 【VMING|Travel Agency Management System - SQL Injection】(CVE-2026-19425, CVSS: 9.8) A SQL Injection vulnerability exists in the Travel Agency Management System developed by VMING. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database contents.
  • Affected Systems:
    • All versions of Travel Agency Management System prior to the August 2026 security update
  • Recommendations:
    • August 2026 security update
  • References:

Computer and Communication Center
Network System Division