6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Basic Information
ID
CVE-2026-10288
Source
VulDB
Published
Jun 1, 2026 at 20:00
Affected Product
Vendor
code-projects
Product
Hotel and Tourism Reservation System
Version
1.0
Affected Versions
code-projects Hotel and Tourism Reservation System 1.0