A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_rates.php. This manipulation of the argument q causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
References
| Link | Resource |
|---|---|
| https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/Resort-Reservation-System---SQLi2.md | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.349772 | Permissions Required VDB Entry |
| https://vuldb.com/?id.349772 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.768999 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2026-03-09 06:16
Updated : 2026-03-09 15:03
NVD link : CVE-2026-3806
Mitre link : CVE-2026-3806
CVE.ORG link : CVE-2026-3806
JSON object : View
Products Affected
oretnom23
- resort_reservation_system
