SQL Injection Vulnerability in itsourcecode Free Hotel Reservation System
CVE-2026-4612
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 23 March 2026
Badges
What is CVE-2026-4612?
A SQL injection vulnerability exists in the itsourcecode Free Hotel Reservation System version 1.0, specifically within the file /hotel/admin/mod_users/index.php?view=edit&id=8. This vulnerability arises when the argument account_id is manipulated, allowing attackers to execute arbitrary SQL queries against the database. The risk of remote exploitation is present, which implies that unauthorized users may leverage this vulnerability to compromise the integrity of the system. Public disclosure of the exploit has heightened the urgency for mitigation measures.
Affected Version(s)
Free Hotel Reservation System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
