CVE-2026-7506
HIGHSourceCodester Hotel Management System check sql injection
Title source: cnaDescription
A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/check. Such manipulation of the argument room_type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
References (5)
Scores
CVSS v3
7.3
EPSS
0.0003
EPSS Percentile
8.5%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
SourceCodester/Hotel Management System
1.0
Published
Apr 30, 2026
Tracked Since
May 01, 2026