A vulnerability identified as critical has been detected in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection.

This vulnerability appears as CVE-2026-2848. The attack may be initiated remotely. In addition, an exploit is available.