Unrated severityNVD Advisory· Published Jun 29, 2026· Updated Jun 29, 2026
itsourcecode Online Hotel Management System controller.php add unrestricted upload
CVE-2026-13553
Description
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected products
1- Range: 1.0
Patches
Vulnerability mechanics
References
6- github.com/Hh-176/CVE/issues/4mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-13553mitrethird-party-advisory
- vuldb.com/submit/843570mitrethird-party-advisory
- itsourcecode.commitreproduct
- vuldb.com/vuln/374561mitrevdb-entrytechnical-description
- vuldb.com/vuln/374561/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.