PT-2026-28657 · Itsourcecode · Free Hotel Reservation System

Binyu

·

Published

2026-03-26

·

Updated

2026-03-29

·

CVE-2026-4875

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions itsourcecode Free Hotel Reservation System version 1.0
Description A manipulation of the image argument in the file '/admin/mod amenities/index.php?view=add' causes unrestricted upload. The attack can be carried out remotely. The exploit has been publicly disclosed. The API endpoint involved is '/admin/mod amenities/index.php?view=add'.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-4875

Affected Products

Free Hotel Reservation System