


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of th…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 23:04:16
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability has been identified in code-projects Hotel and Tourism Reservation System version 1.0. The vulnerability exists in an unknown function within the tour.php file of the GET Parameter Handler component. Attackers can exploit this by manipulating the 'tour' argument to execute SQL injection attacks. The vulnerability can be exploited remotely without authentication. Public exploits are available, making this an actively exploitable security issue that poses significant risk to affected systems.
Technical details
Mitigation steps:
Affected products:
Hotel and Tourism Reservation System 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10290
https://code-projects.org/
https://github.com/Xmyronn/Hotel-and-Tourism-Reservation-System---Unauthenticated-SQL-Injection.git
https://vuldb.com/cve/CVE-2026-10290
https://vuldb.com/submit/825939
https://vuldb.com/vuln/367583
https://vuldb.com/vuln/367583/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
