PT-2026-45553 · Code Projects · Hotel/Tourism Reservation System

·

CVE-2026-10288

·

Published

2026-06-01

·

Updated

2026-07-22

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Hotel and Tourism Reservation System version 1.0
Description An issue in the Admin Login component allows remote attackers to achieve improper authentication. This occurs through the manipulation of the Password argument within the password verify() function located in the '/admin/login.php' endpoint.
Recommendations As a temporary workaround, restrict access to the '/admin/login.php' endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10288

Affected Products

Hotel/Tourism Reservation System