
A pair of security researchers say they discovered a vulnerability in login systems for records that the Transportation Security Administration (TSA) uses to verify airline crew members at airport security checkpoints. The bug let anyone with a “basic knowledge of SQL injection” add themselves to airline rosters, potentially letting them breeze through security and into the cockpit of a commercial airplane, researcher Ian Carroll wrote in a blog post in August.
Carroll and his partner, Sam Curry, apparently discovered the vulnerability while probing the third-party website of a vendor called FlyCASS that provides smaller airlines access to the TSA’s Known Crewmember (KCM) system and Cockpit Access Security System (CASS). They found that when they put a simple apostrophe into the username field, they got a MySQL error.
This was a very bad sign, as it seemed the username was directly interpolated into the login SQL query. Sure enough, we had discovered SQL injection and were able to use sqlmap to confirm the issue. Using the username of ‘ or ‘1’=’1 and password of ‘) OR MD5(‘1’)=MD5(‘1, we were able to login to FlyCASS as an administrator of Air Transport International!
Once they were in, Carroll writes that there was “no further check or authentication” preventing them from adding crew records and photos for any airline that uses FlyCASS. Anyone who might have used the vulnerability could present a fake employee number to get through a KCM security checkpoint, the blog says.
TSA press secretary R. Carter Langston denied that, telling Bleeping Computer that the agency “does not solely rely on this database to authenticate flight crew, and that “only verified crewmembers are permitted access to the secure area in airports.”
Khamrah by Lattafa for Men - 3.4 oz EDP Spray
4% OffGhost Sweetheart Eau de Toilette | Pineapple, Jasmine and Sandalwood | Perfume for Women 50 ml
50% OffMarc Jacobs Dot Eau De Parfum for Women, 100 ml
42% OffTed Baker W Eau de Toilette for Her, Fig Leaf, White Peony and Violet Top Notes, Pink Orchid and Raspberry Middle Notes, 75ml
£11.77 (£15.69 / 100 ml) (as of 25/04/2026 03:01 GMT +01:00 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)Ted Baker Woman Pink Eau de Toilette Spray Floral Green Feminine Fragrance, Opening Notes are Fresh Peach, Bergamot and Tangerine with Warm Musk, Vanilla and Vetiver Base, 100ml
11% OffVera Wang Princess Eau de Toilette - 30 ml
Choco Musk 50ml Eau De Parfum for men and women | Chocolate Musk by Jannat Aromas
17% OffChristina Aguilera Signature Eau de Parfum (50ml) Floral, Fruity & Exotic Scent, Luxury Fragrance for Women
9% OffCalvin Klein - Eau De Toilette CKIN2U - Calvin Klein Women, Ladies Perfume, Women's Perfume, Calvin Klein Perfume, Calvin Klein One - 150 ml
5% OffJimmy Choo Flash Eau de Parfum, 60 ml (Pack of 1)
3% OffFruit of the Loom Men's Heavy T Shirt, White, XL UK
28% OffATNKE LED Lighted Beanie Cap,USB Rechargeable Running Hat Ultra Bright 4 LED Waterproof Light Winter Warm Gifts for Men and Women/Pink
Now retrieving the rating.
17% OffMen's 1/4 Zip Pullover UK Sale Clearance, Fleece Sweatshirt Casual Jumper Long Sleeve T-shirt Top Stand Collar Sweater Plain Pullover Sports Leisure Workwear Quarter Zip Sweater Lightweight Jumpers
Now retrieving the rating.
£5.88 (as of 12/11/2025 00:52 GMT +01:00 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)