CVE-2026-13553: itsourcecode Online Hotel Management System controller.php add unrestricted upload
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/modamenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict external (internet) access to /admin/mod_amenities/controller.php?action=add so only trusted IPs can reach the endpoint.
- Operational
If unrestricted upload is suspected or confirmed, review and remove any web-accessible files uploaded via /admin/mod_amenities/controller.php?action=add, then rotate any affected credentials and verify application integrity.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13553?
The severity of CVE-2026-13553 is classified as high, with a score of 7.3.
How do I fix CVE-2026-13553?
To fix CVE-2026-13553, restrict file uploads in the /admin/mod_amenities/controller.php script to acceptable file types and implement file size limits.
What type of vulnerability is CVE-2026-13553?
CVE-2026-13553 is a malicious file upload vulnerability that allows unauthorized file uploads.
Can CVE-2026-13553 be exploited remotely?
Yes, CVE-2026-13553 can be exploited remotely, allowing attackers to manipulate the image argument to upload malicious files.
Which software is affected by CVE-2026-13553?
CVE-2026-13553 affects itsourcecode Online Hotel Management System version 1.0.