Junglewise Threat Intelligence

CVE-2026-14762: code-projects Hotel and Tourism Reservation SQL injection in rooms.php

CVE-2026-14762 · Severity: high · CVSS 7.3 · Published 2026-07-05

Technologies: Code-Projects Hotel and Tourism Reservation System. Vendors: Code-Projects.

Executive brief

A vulnerability exists in the Hotel and Tourism Reservation system, a web application used for managing hotel bookings. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially exposing customer information, reservation details, and administrative credentials. This could lead to a complete data breach or disruption of the reservation service.

Technical details

A time-based blind SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation 1.0 within the '/admin/rooms.php' file. The vulnerability is rooted in the improper neutralization of the 'delete' GET parameter used in the Room Management component. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests containing SQL payloads (e.g., using XOR and SLEEP functions) to extract sensitive information from the database. A public exploit is available, and remediation involves implementing prepared statements with parameterized queries.

Affected products

  • code-projects Hotel and Tourism Reservation 1.0

Timeline

  • 2026-07-05: disclosed
  • 2026-07-05: advisory

References

Related threats