Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.3
janobe Resort Reservation System SQL Injection Risk
CVE-2026-3806
Summary
The janobe Resort Reservation System 1.0 may allow attackers to manipulate data if they send malicious input to the /room_rates.php file. This could happen if users enter specially crafted data. To minimize risk, update the system to the latest version or apply the recommended fixes.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| oretnom23 | resort_reservation_system | 1.0 | – |
Original title
A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_rates.php. This manipulation of the argument q ca...
Original description
A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_rates.php. This manipulation of the argument q causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
nvd CVSS2.0
6.5
nvd CVSS3.1
6.3
nvd CVSS4.0
5.3
Vulnerability type
CWE-74
Injection
CWE-89
SQL Injection
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026