CVE-2026-55740: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Nur-Alam39 bus-ticket
Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated directly into a MySQL query (select * from bus_info where id=) without sanitization, escaping, or parameterization, and in a numeric (unquoted) context.
AI Analysis
Technical Summary
CVE-2026-55740 is an SQL injection vulnerability in the Nur-Alam39 bus-ticket application. The issue exists in bus_info.php where the busid parameter received via HTTP POST is concatenated directly into a numeric MySQL query without any input sanitization or parameterization. This improper neutralization of special elements in SQL commands (CWE-89) allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to full database compromise. The vulnerability has a CVSS 3.1 base score of 9.8, indicating critical severity. There is no vendor advisory or patch available at this time, and no known exploits in the wild have been reported.
Potential Impact
Successful exploitation of this vulnerability can lead to unauthorized disclosure, modification, or deletion of data within the backend database. Because the vulnerability is unauthenticated and remotely exploitable over the network, it poses a critical risk to the confidentiality, integrity, and availability of the affected system's data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to implement input validation and parameterized queries to prevent SQL injection. Restricting access to the vulnerable endpoint and monitoring for suspicious activity may also help reduce risk.
CVE-2026-55740: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Nur-Alam39 bus-ticket
Description
Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated directly into a MySQL query (select * from bus_info where id=) without sanitization, escaping, or parameterization, and in a numeric (unquoted) context.
CVSS v3.1
Score 9.8critical
Affected software
Nur-Alam39
bus-ticket
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55740 is an SQL injection vulnerability in the Nur-Alam39 bus-ticket application. The issue exists in bus_info.php where the busid parameter received via HTTP POST is concatenated directly into a numeric MySQL query without any input sanitization or parameterization. This improper neutralization of special elements in SQL commands (CWE-89) allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to full database compromise. The vulnerability has a CVSS 3.1 base score of 9.8, indicating critical severity. There is no vendor advisory or patch available at this time, and no known exploits in the wild have been reported.
Potential Impact
Successful exploitation of this vulnerability can lead to unauthorized disclosure, modification, or deletion of data within the backend database. Because the vulnerability is unauthenticated and remotely exploitable over the network, it poses a critical risk to the confidentiality, integrity, and availability of the affected system's data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to implement input validation and parameterized queries to prevent SQL injection. Restricting access to the vulnerable endpoint and monitoring for suspicious activity may also help reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-06-17T12:59:17.621Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a33875bf198dc38c1370f2b
Added to database: 06/18/2026, 05:51:23 UTC
Last enriched: 08/13/2026, 16:38:15 UTC
Last updated: 09/16/2026, 13:07:30 UTC
Views: 189
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.