CVE-2026-10288

HIGH

code-projects Hotel and Tourism Reservation System 1.0 - Improper Authentication via Admin Login Password Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-10288. PoCs published by Xmyronn.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-10288, an authentication bypass vulnerability in the Hotel and Tourism Reservation System 1.0. The root cause is an inverted conditional check on `password_verify()`, allowing unauthenticated remote attackers to gain admin access with any incorrect password.

Description

A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Exploits (1)

github WRITEUP
by Xmyronn · poc
https://github.com/Xmyronn/CVE-2026-10288-AUTH-BYPASS

This repository provides a detailed technical analysis of CVE-2026-10288, an authentication bypass vulnerability in the Hotel and Tourism Reservation System 1.0. The root cause is an inverted conditional check on `password_verify()`, allowing unauthenticated remote attackers to gain admin access with any incorrect password.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Hotel and Tourism Reservation System 1.0
No auth needed
Prerequisites: valid admin email address · any incorrect password
devstral-2 · analyzed Jun 05, 2026 Full analysis →

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/vuln/367581
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/vuln/367581/cti
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/cve/CVE-2026-10288
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/submit/825786
Various Sources product
https://code-projects.org/

Scores

CVSS v3 7.3
EPSS 0.0012
EPSS Percentile 30.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
code-projects/Hotel and Tourism Reservation System 1.0
Published Jun 01, 2026
Tracked Since Jun 02, 2026