


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php.…
Published:
15 maart 2026 om 23:00:00
Alert date:
16 maart 2026 om 16:21:26
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been discovered in itsourcecode Free Hotel Reservation System 1.0. The flaw affects the /hotel/admin/mod_reports/index.php file through manipulation of the Home argument. The vulnerability can be exploited remotely and a public exploit has been published. This allows attackers to potentially access, modify, or extract sensitive database information from the hotel management system. The vulnerability poses a high risk due to its remote exploitability and availability of public exploit code.
Technical details
Mitigation steps:
Affected products:
Free Hotel Reservation System 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4237
https://github.com/yuji0903/silver-guide/issues/14
https://itsourcecode.com/
https://vuldb.com/?ctiid.351179
https://vuldb.com/?id.351179
https://vuldb.com/?submit.771243
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
