CVE-2026-7506

· NIST NVD ↗

A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/check. Such manipulation of the argument room_type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

HIGH
CVSS severity
7.3
CVSS base score
2026-04-30
Published

CWE codes

CWE-74CWE-89

Sources