Junglewise Threat Intelligence

CVE-2026-86217: code-projects Hotel and Tourism Reservation information disclosure via exposed SQL file

CVE-2026-86217 · Severity: medium · CVSS 5.3 · Published 2026-09-06

Vendors: Code-Projects.

Executive brief

Hotel and Tourism Reservation is a PHP-based hotel booking system used by businesses to manage reservations and customer data. The application stores its SQL database backup file in a web-accessible directory, allowing unauthenticated attackers to download the database and access sensitive information including customer details, booking records, and potentially credentials.

Technical details

This vulnerability is an information disclosure flaw caused by improper file placement—a SQL database backup file (hotel_db.sql) is stored in the web root directory (/ht/) and is directly accessible via HTTP GET requests without authentication. The vulnerable component is the Database Backup Handler, which fails to restrict access to database files. An unauthenticated remote attacker can discover and download the SQL file, gaining read access to the entire database structure and contents. The attack requires no special privileges or user interaction and can be executed remotely. Remediation involves removing SQL files from the web root, storing databases outside the document root, and implementing access controls via web server configuration.

Affected products

  • code-projects Hotel and Tourism Reservation 1.0

Timeline

  • 2026-09-06: disclosed
  • exploited: exploit is public and may be used

References

Related threats