CVE-2026-86217
MEDIUMCVSS 5.3Description
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.
Timeline
Published:September 6th, 2026 3:17 PM
Last modified:September 6th, 2026 3:17 PM
CVSS Scoring
CVSS v3: 5.3 (MEDIUM)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2: 5.0
References & Reports
Advisories, patches, and third-party reports
- https://code-projects.org/
- https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Hotel%20and%20Tourism%20Reservation%20System%20%E2%80%93%20Sensitive%20Information%20Disclosure%20via%20Exposed%20SQL%20Database%20File.md
- https://vuldb.com/cve/CVE-2026-86217
- https://vuldb.com/submit/897301
- https://vuldb.com/vuln/399355
- https://vuldb.com/vuln/399355/cti
Source: NIST NVD · Data may lag official sources by up to one minute