PT-2026-45605 · Code Projects · Hotel/Tourism Reservation System

Imad Alvi

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-10290

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-10290

Affected Products

Hotel/Tourism Reservation System