Executive brief
A vulnerability exists in the itsourcecode Online Hotel Management System, a software package used for managing hotel operations. An attacker can upload malicious files to the server without needing to log in. This could allow a remote attacker to take full control of the server, steal sensitive guest data, or disrupt hotel operations.
Technical details
An arbitrary file upload vulnerability exists in /admin/mod_amenities/controller.php?action=add due to insufficient validation of the 'image' parameter. The application fails to properly verify file extensions and content, relying on easily spoofed 'Content-Type' and 'Content-Disposition' headers. An unauthenticated remote attacker can exploit this by sending a specially crafted POST request containing a PHP shell disguised as an image file. Once uploaded, the script can be accessed directly via the web server, allowing for remote code execution (RCE) and full server takeover. A public proof-of-concept (PoC) is available.
Affected products
- itsourcecode Online Hotel Management System 1.0
Timeline
- 2026-05-30: disclosed: Vulnerability details and PoC shared on GitHub.
- 2026-06-29: advisory: CVE-2026-13553 published.