CVE-2026-4876: itsourcecode Free Hotel Reservation System index.php sql injection
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/modamenities/index.php?view=editpic. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4876?
The severity of CVE-2026-4876 is considered high due to the potential for SQL injection exploitation.
How do I fix CVE-2026-4876?
To fix CVE-2026-4876, sanitize and validate all user inputs in the affected index.php file to prevent SQL injection.
What systems are affected by CVE-2026-4876?
CVE-2026-4876 affects version 1.0 of the itsourcecode Free Hotel Reservation System.
Can CVE-2026-4876 lead to data breaches?
Yes, CVE-2026-4876 can potentially lead to unauthorized access to the database, resulting in data breaches.
What is the attack vector for CVE-2026-4876?
The attack vector for CVE-2026-4876 involves manipulating the 'ID' argument in the /admin/mod_amenities/index.php file.