PHP Application Vulnerability in Meeting Room Booking System by MRBS
CVE-2026-46382
8.7HIGH
What is CVE-2026-46382?
A security issue exists in the Meeting Room Booking System (MRBS), a widely used PHP application for booking meeting rooms. Prior to version 1.12.2, the system fails to properly validate user-supplied private/local URIs, allowing unauthorized fetching of sensitive information. This oversight exposes the application to potential misuse and data leaks. Users are highly encouraged to update to version 1.12.2, which includes a fix addressing this vulnerability. Unfortunately, no known workarounds are available to mitigate this issue, making immediate action necessary for those using affected versions.
Affected Version(s)
mrbs-code < 1.12.2
