Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Unrestricted File Upload in Janobe Resort Reservation System

CVE-2026-3800
Summary

A security flaw in the Janobe Resort Reservation System allows an attacker to upload any file they want without restriction. This could lead to malicious files being uploaded to the system, which could compromise the security of the website. Update the system to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
oretnom23 resort_reservation_system 1.0 –
Original title
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument im...
Original description
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
nvd CVSS2.0 6.5
nvd CVSS3.1 6.3
nvd CVSS4.0 5.3
Vulnerability type
CWE-284 Improper Access Control
CWE-434 Unrestricted File Upload
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026