Junglewise Threat Intelligence

CVE-2026-14763: code-projects Hotel and Tourism Reservation SQL injection in tour_reserves.php

CVE-2026-14763 · Severity: high · CVSS 7.3 · Published 2026-07-05

Technologies: Code-Projects Hotel and Tourism Reservation System. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Hotel and Tourism Reservation system, a software package used for managing travel and lodging bookings. An attacker can exploit this flaw to gain unauthorized access to the underlying database without needing a username or password. This could lead to the theft of sensitive customer information, reservation details, and administrative credentials, potentially resulting in a full system takeover.

Technical details

A time-based blind SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation 1.0 within the 'Tour Reservations Page' component. The flaw is located in the /admin/tour_reserves.php file and is triggered by improper neutralization of the 'tour' POST parameter. An unauthenticated remote attacker can exploit this by sending specially crafted SQL queries, allowing for the enumeration and extraction of the entire database. A public exploit involving the 'sleep' function has been disclosed, confirming the vulnerability's impact on data confidentiality and integrity. Remediation requires the implementation of prepared statements and parameterized queries.

Affected products

  • code-projects Hotel and Tourism Reservation 1.0

Timeline

  • 2026-07-05: disclosed
  • 2026-07-05: advisory

References

Related threats