CVE-2026-11342

HIGH

code-projects Hotel and Tourism Reservation System details.php sql injection

Title source: cna
STIX 2.1

Description

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-368883 | code-projects Hotel and Tourism Reservation System details.php sql injection
https://vuldb.com/vuln/368883
Signature, Permissions Required signature permissions-required
VDB-368883 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/368883/cti
Third Party Advisory third-party-advisory
CVE-2026-11342 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-11342
Third Party Advisory third-party-advisory
Submit #832902 | code-projects Hotel And Tourism Reservation System 1.0 SQL Injection
https://vuldb.com/submit/832902
Product product
https://code-projects.org/

Scores

CVSS v3 7.3
EPSS 0.0041
EPSS Percentile 32.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
code-projects/Hotel and Tourism Reservation System 1.0
Published Jun 05, 2026
Tracked Since Jun 05, 2026