CVE-2026-4612: itsourcecode Free Hotel Reservation System Parameter index.php sql injection
A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/modusers/index.php?view=edit&id=8 of the component Parameter Handler. The manipulation of the argument accountid leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4612?
CVE-2026-4612 has a high severity rating due to its potential for SQL injection exploitation.
How do I fix CVE-2026-4612?
To fix CVE-2026-4612, validate and sanitize user inputs in the parameter handler of the application.
What systems are affected by CVE-2026-4612?
The CVE-2026-4612 vulnerability affects itsourcecode Free Hotel Reservation System version 1.0.
Can CVE-2026-4612 allow unauthorized access?
Yes, CVE-2026-4612 can potentially allow unauthorized access to the database due to SQL injection.
Is CVE-2026-4612 easy to exploit?
CVE-2026-4612 is relatively easy to exploit for individuals with basic knowledge of SQL injection techniques.