← volver
CVE-2026-10290mediumCWE-74CWE-89

code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql injection

33Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 6.9epss 0.3%
de la publicación al arma0 días
Publicada en NVD1 jun
1ª PoC11 may
probabilidad de explotación
0.3%top 76% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.