Back to VulnFeed / CVE-2026-7506
root@hackertop:~/vulnfeed/CVE-2026-7506#
CVE-2026-7506 MEDIUM SQLi/Injection ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

SourceCodester Hotel Management System 1.0 check room_type sql injection

Hotel Management System 21d ago Impact pending confirmation
LIFECYCLE
6.6 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability classified as critical has been found in SourceCodester Hotel Management System 1.0 (Hospitality Software). This affects an unknown code of the file /index.php/reservation/check. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
Root Cause Analysis
The manipulation of the argument room_type with an unknown input leads to a unknown weakness. CWE is classifying the issue as CWE-89. The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

Impact: This is going to have an impact on confidentiality, integrity, and availability.

Exploit: The exploit is shared for download at github.com. It is declared as proof-of-concept.

Countermeasure: There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-7506 · CVSS 6.6 · Active Threat