Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
Tushar-2223 Hotel Management System SQL Injection Risk
CVE-2026-6142
Summary
An attacker could potentially inject malicious SQL code into the system of Tushar-2223 Hotel Management System, allowing them to access sensitive data or take control of the system. This vulnerability is present in a specific function used by administrators, but it can be exploited remotely. If not addressed, an attacker could use publicly available exploits to compromise the system.
Original title
A vulnerability was identified in tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. Affected by this vulnerability is an unknown functionality of the file /admin/r...
Original description
A vulnerability was identified in tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. Affected by this vulnerability is an unknown functionality of the file /admin/roomdelete.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
nvd CVSS2.0
7.5
nvd CVSS3.1
7.3
nvd CVSS4.0
6.9
Vulnerability type
CWE-74
Injection
CWE-89
SQL Injection
Published: 13 Apr 2026 · Updated: 13 Apr 2026 · First seen: 13 Apr 2026