Executive brief
A vulnerability exists in the itsourcecode Online Hotel Management System, a software package used for managing hotel bookings and operations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive customer information or the disruption of hotel services. This attack can be carried out remotely without requiring any user login credentials.
Technical details
A SQL injection vulnerability exists in itsourcecode Online Hotel Management System 1.0 within the '/admin/mod_amenities/controller.php' file. The root cause is the improper sanitization of the 'amen_id' parameter when the 'action' is set to 'edit'. An unauthenticated remote attacker can send a specially crafted POST request containing malicious SQL commands (such as time-based blind payloads) to manipulate database queries. Successful exploitation allows for unauthorized data retrieval, data modification, or full database compromise. A public exploit (PoC) using sqlmap has been disclosed.
Affected products
- itsourcecode Online Hotel Management System 1.0
Timeline
- 2026-05-30: disclosed: Initial disclosure on GitHub by researcher Hh-176
- 2026-06-29: advisory: NVD and VulDB publication date