Unrated severityNVD Advisory· Published Jun 29, 2026· Updated Jun 29, 2026
itsourcecode Online Hotel Management System controller.php edit sql injection
CVE-2026-13552
Description
A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the argument amen_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Patches
Vulnerability mechanics
References
6- github.com/Hh-176/CVE/issues/3mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-13552mitrethird-party-advisory
- vuldb.com/submit/843569mitrethird-party-advisory
- itsourcecode.commitreproduct
- vuldb.com/vuln/374560mitrevdb-entrytechnical-description
- vuldb.com/vuln/374560/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.