Aller au contenu

Fiche vulnérabilité

CVE-2026-3800 : faille élevée oretnom23 resort reservation system (CVSS 8.8)

Description

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
9 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • oretnom23 resort reservation system

Références

Rechercher une autre vulnérabilité dans la base CVE