Junglewise Threat Intelligence

CVE-2026-13555: itsourcecode Online Hotel Management System SQL injection in controller.php

CVE-2026-13555 · Severity: high · CVSS 7.3 · Published 2026-06-29

Technologies: Itsourcecode Online Hotel Management System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Online Hotel Management System, a software package used for managing hotel operations and guest records. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive guest information or the disruption of hotel services. Because the vulnerability does not require a password to exploit, it poses a significant risk to data privacy and business continuity.

Technical details

A SQL injection vulnerability exists in itsourcecode Online Hotel Management System 1.0 within the '/admin/mod_users/controller.php' component. The root cause is the failure to sanitize the 'Name' POST parameter when the 'action' is set to 'add'. A remote, unauthenticated attacker can exploit this by sending specially crafted SQL queries, leading to boolean-based or time-based blind SQL injection. This allows for unauthorized database enumeration, data extraction, and potential full system compromise. A public exploit (PoC) using sqlmap has been disclosed.

Affected products

  • itsourcecode Online Hotel Management System 1.0

Timeline

  • 2026-05-30: disclosed: Vulnerability details and PoC shared on GitHub by researcher Hh-176
  • 2026-06-29: advisory: NVD and VulDB publish advisory details

References

Related threats