A vulnerability was found in Win Men Intermational Travel Agency Management System. It has been classified as critical. The affected element is an unknown function. Performing a manipulation results in sql injection.

This vulnerability is reported as CVE-2026-19425. The attack is possible to be carried out remotely. No exploit exists.