CVE-2026-11342: code-projects Hotel and Tourism Reservation System details.php sql injection

Published Jun 5, 2026
·
Updated

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected Software

1 affected component
Code-projects Hotel and Tourism Reservation System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Modify /details.php so the 'room' argument is strictly validated and sanitized and all database access uses parameterized/prepared statements (do not concatenate user input into SQL) to prevent SQL injection.

    Hotel and Tourism Reservation System 1.0 - /details.php room parameter handling = validate and sanitize input; use parameterized (prepared) SQL queries
  2. Compensating control

    If code cannot be fixed immediately, deploy a web application firewall rule or input-filtering at the edge to block malicious payloads targeting the 'room' parameter and/or restrict access to /details.php to trusted IPs until the application is remediated.

  3. Operational

    Investigate logs and database activity for signs of exploitation (suspicious queries, unexpected data changes). If compromise is found, perform incident response (containment, eradication, recovery) and apply the code fixes as soon as possible.

Event History

Jun 5, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11342?

The severity of CVE-2026-11342 is categorized as high with a score of 7.3.

2

How do I fix CVE-2026-11342?

To fix CVE-2026-11342, it is recommended to sanitize user inputs and implement prepared statements to prevent SQL injection.

3

What type of vulnerability is CVE-2026-11342?

CVE-2026-11342 is a SQL injection vulnerability that allows an attacker to manipulate database queries.

4

Can CVE-2026-11342 be exploited remotely?

Yes, CVE-2026-11342 can be exploited remotely through the details.php file by manipulating the room argument.

5

Which software is affected by CVE-2026-11342?

CVE-2026-11342 affects version 1.0 of the Code-projects Hotel and Tourism Reservation System.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203