PT-2026-30421 · Itsourcecode · Free Hotel Reservation System

Zzzhe

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5551

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5551

Affected Products

Free Hotel Reservation System