Unrated severityNVD Advisory· Published Jun 29, 2026· Updated Jun 29, 2026
itsourcecode Online Hotel Management System controller.php add sql injection
CVE-2026-13555
Description
A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Patches
Vulnerability mechanics
References
6- github.com/Hh-176/CVE/issues/6mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-13555mitrethird-party-advisory
- vuldb.com/submit/843585mitrethird-party-advisory
- itsourcecode.commitreproduct
- vuldb.com/vuln/374563mitrevdb-entrytechnical-description
- vuldb.com/vuln/374563/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.