PT-2026-36211 · Sourcecodester · Hotel Management System

Wangzhongyang085

·

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2026-7506

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/check. Such manipulation of the argument room type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7506

Affected Products

Hotel Management System