


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.ph…
Published:
4 april 2026 om 22:00:00
Alert date:
5 april 2026 om 10:00:40
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability (CVE-2026-5551) has been discovered in itsourcecode Free Hotel Reservation System 1.0. The flaw affects the /hotel/admin/login.php file in the Parameter Handler component, where manipulation of the email argument leads to SQL injection. The vulnerability can be exploited remotely and a public exploit has been released, making it actively exploitable. This represents a critical security risk as it affects the admin login functionality and could lead to complete system compromise.
Technical details
Mitigation steps:
Affected products:
itsourcecode Free Hotel Reservation System 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5551
https://github.com/jasonwong666/cve/issues/1
https://itsourcecode.com/
https://vuldb.com/submit/782845
https://vuldb.com/vuln/355315
https://vuldb.com/vuln/355315/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
