A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. It has been declared as critical. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection.

This vulnerability is identified as CVE-2026-3711. The attack can be executed remotely. Additionally, an exploit exists.