A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulation of the argument from results in sql injection.
This vulnerability was named CVE-2026-3736. The attack may be initiated remotely. In addition, an exploit is available.