Junglewise Threat Intelligence

CVE-2026-14754: code-projects Hotel and Tourism Reservation SQL injection in add_room.php

CVE-2026-14754 · Severity: high · CVSS 7.3 · Published 2026-07-05

Technologies: Code-Projects Hotel and Tourism Reservation System. Vendors: Code-Projects.

Executive brief

A security vulnerability has been identified in the Hotel and Tourism Reservation system, a software package used for managing hotel bookings and room inventory. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive information such as reservation details, pricing, and room descriptions. This could lead to significant operational disruption and the compromise of business data.

Technical details

A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation 1.0 within the '/admin/add_room.php' file. The flaw is caused by improper neutralization of special elements in SQL commands (CWE-89) when handling multiple parameters, including 'delete_image', 'edit', 'description', 'number', 'price', 'rooms', and 'type'. A remote attacker can exploit this by sending specially crafted requests to the affected script without requiring prior authentication. Successful exploitation allows the attacker to read from or write to the database, potentially leading to a full compromise of the application's data. A public exploit has been reported for this vulnerability.

Affected products

  • code-projects Hotel and Tourism Reservation 1.0

Timeline

  • 2026-07-05: disclosed
  • 2026-07-05: advisory

References

Related threats