Description
Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers to inject malicious SQL commands. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to compromise the database management system and web application without user interaction.
Exploits (1)
exploitdb
WORKING POC
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/48417
References (4)
Scores
CVSS v3
7.1
EPSS
0.0003
EPSS Percentile
10.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (1)
Fishing Reservation System/Fishing Reservation System
7.5
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026