Unrated severityNVD Advisory· Published Jul 5, 2026· Updated Jul 6, 2026
code-projects Hotel and Tourism Reservation add_room.php sql injection
CVE-2026-14754
Description
A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Affected products
1- Range: 1.0
Patches
Vulnerability mechanics
References
6- medium.com/@avdzav10/sql-injection-in-hotel-and-tourism-reservation-system-php-1-0-admin-add-room-php-25149909c16amitrebroken-linkexploit
- vuldb.com/cve/CVE-2026-14754mitrethird-party-advisory
- vuldb.com/submit/850344mitrethird-party-advisory
- code-projects.orgmitreproduct
- vuldb.com/vuln/376343mitrevdb-entrytechnical-description
- vuldb.com/vuln/376343/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.