CVE-2026-3730: itsourcecode Free Hotel Reservation System index.php sql injection
A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/modamenities/index.php?view=edit. Performing a manipulation of the argument amenid/rmtypeid results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3730?
CVE-2026-3730 is classified as a high-severity SQL injection vulnerability affecting itsourcecode Free Hotel Reservation System.
How do I fix CVE-2026-3730?
To remediate CVE-2026-3730, it is essential to sanitize and validate all input parameters in the affected index.php file.
What software is affected by CVE-2026-3730?
CVE-2026-3730 affects itsourcecode Free Hotel Reservation System version 1.0 specifically in the mod_amenities module.
What type of vulnerability is CVE-2026-3730?
CVE-2026-3730 is an SQL injection vulnerability that allows attackers to manipulate SQL queries.
Can CVE-2026-3730 lead to a data breach?
Yes, due to its nature, CVE-2026-3730 could potentially allow an attacker to execute arbitrary SQL commands and access sensitive data.