Junglewise Threat Intelligence

CVE-2026-36942: Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php.

CVE-2026-36942 · Severity: low · CVSS 2.7 · Published 2026-04-13

Vendors: SourceCodester.

Executive brief

The Online Resort Management System, a web application used for managing resort operations, contains a security flaw in its administrative interface. An attacker with administrative credentials can exploit this vulnerability to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive business information or guest data stored within the system.

Technical details

A SQL injection vulnerability exists in Sourcecodester Online Resort Management System v1.0 within the '/orms/admin/activities/manage_activity.php' file. The 'id' GET parameter is not properly sanitized before being used in a database query, allowing for UNION-based SQL injection. An attacker with high privileges (administrative access) can send crafted HTTP requests to leak sensitive information, such as the database name or other table data. The vulnerability is confirmed in environments running PHP 8.1 via XAMPP. No official patch is currently documented.

Affected products

  • Sourcecodester Online Resort Management System 1.0

Timeline

  • 2026-04-13: disclosed: Initial vulnerability report published on GitHub.
  • 2026-04-13: advisory: CVE-2026-36942 assigned and published.

References