Junglewise Threat Intelligence

CVE-2026-6142: tushar-2223 Hotel Management System SQL injection in roomdelete.php

CVE-2026-6142 · Severity: high · CVSS 7.3 · Published 2026-04-13

Executive brief

A security vulnerability exists in the tushar-2223 Hotel Management System, a software package used for managing hotel operations. An attacker can remotely manipulate database queries to access or delete sensitive information without needing a username or password. This could lead to the theft of guest data, loss of administrative credentials, or the deletion of critical room and booking records.

Technical details

An unauthenticated time-based blind SQL injection vulnerability exists in the tushar-2223 Hotel Management System up to commit bb1f3b3. The vulnerability is located in the /admin/roomdelete.php endpoint, where the 'id' parameter is directly concatenated into a SQL query without sanitization or the use of prepared statements. Additionally, the administrative endpoint fails to enforce session authentication, allowing remote, unauthenticated attackers to execute arbitrary SQL commands. This can be exploited to exfiltrate the entire database or perform destructive operations. A public exploit (PoC) using sqlmap is available. As of the advisory date, the maintainer has not responded to the issue report.

Affected products

  • tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15

Timeline

  • 2026-04-02: disclosed: Vulnerability reported to the developer via GitHub issue and public Gist published.
  • 2026-04-13: advisory: CVE-2026-6142 published.

References