PT-2026-25704 · Itsourcecode · Free Hotel Reservation System

Yu_Ji

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-4237

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod reports/index.php. Executing a manipulation of the argument Home can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-4237

Affected Products

Free Hotel Reservation System