CVE-2026-13552: high vulnerability (CVSS 7.3)
CVE-2026-13552 affects itsourcecode Online Hotel Management System 1.0, allowing remote SQL injection via /admin/mod_amenities/controller.php?action=edit. Public exploit availability heightens the risk of unauthorized data access or system compromise.
Prioritize patching or isolating this system immediately. Monitor for unusual database activity and consider deploying web application firewalls (WAF) with SQL injection rules to mitigate further exploitation.
CVE-2026-13552 is a high-severity vulnerability (CVSS 7.3) in itsourcecode Online Hotel Management System 1.0. It involves SQL injection in the argument amen_id of the file /admin/mod_amenities/controller.php?action=edit.
The vulnerability enables remote attackers to manipulate database queries, potentially exposing sensitive information or allowing unauthorized system modifications. A public exploit has been released, increasing the likelihood of active exploitation.
Administrators should patch or disable affected components immediately. Additional defenses, such as input validation, WAF deployment, and real-time monitoring, can help mitigate risks until a permanent fix is applied.