A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. It has been declared as critical. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno results in sql injection.

This vulnerability was named CVE-2026-3723. The attack may be performed from remote. In addition, an exploit is available.