Junglewise Threat Intelligence

CVE-2026-13553: itsourcecode Online Hotel Management System unrestricted upload in mod_amenities

CVE-2026-13553 · Severity: high · CVSS 7.3 · Published 2026-06-29

Technologies: Itsourcecode Online Hotel Management System. Vendors: Itsourcecode.

Executive brief

A vulnerability exists in the itsourcecode Online Hotel Management System, a software package used for managing hotel operations. An attacker can upload malicious files to the server without needing to log in. This could allow a remote attacker to take full control of the server, steal sensitive guest data, or disrupt hotel operations.

Technical details

An arbitrary file upload vulnerability exists in /admin/mod_amenities/controller.php?action=add due to insufficient validation of the 'image' parameter. The application fails to properly verify file extensions and content, relying on easily spoofed 'Content-Type' and 'Content-Disposition' headers. An unauthenticated remote attacker can exploit this by sending a specially crafted POST request containing a PHP shell disguised as an image file. Once uploaded, the script can be accessed directly via the web server, allowing for remote code execution (RCE) and full server takeover. A public proof-of-concept (PoC) is available.

Affected products

  • itsourcecode Online Hotel Management System 1.0

Timeline

  • 2026-05-30: disclosed: Vulnerability details and PoC shared on GitHub.
  • 2026-06-29: advisory: CVE-2026-13553 published.

References

Related threats