CVE-2026-13555: itsourcecode Online Hotel Management System controller.php add sql injection
A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/modusers/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13555?
The severity of CVE-2026-13555 is high, rated at 7.3.
What type of vulnerability is CVE-2026-13555?
CVE-2026-13555 is classified as an SQL Injection vulnerability.
How can CVE-2026-13555 be exploited?
An attacker can exploit CVE-2026-13555 remotely by manipulating the 'Name' argument in the /admin/mod_users/controller.php?action=add file.
How do I fix CVE-2026-13555?
To fix CVE-2026-13555, ensure proper input validation and prepared statements are implemented in the affected code.
Which software is affected by CVE-2026-13555?
CVE-2026-13555 affects itsourcecode Online Hotel Management System version 1.0.