CVE-2026-86217: code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure
Published Sep 6, 2026
·Updated
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hoteldb%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
1 affected component
Code-projects Hotel and Tourism Reservation in PHP=1.0
Event History
Sep 6, 2026
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can this be exploited remotely without authentication or user interaction?
Yes. The vulnerability is remotely reachable, and the supplied vector indicates no privileges or user interaction are required.
2
Is exploit code available?
Yes. The exploit is public and may be used.
3
Which deployments should be prioritized for assessment?
Deployments of code-projects Hotel and Tourism Reservation in PHP 1.0 should be assessed, particularly where the Database Backup Handler and the /ht/hotel_db%20(1).sql file are accessible.