CVE-2026-86217 Details
Description
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.
A sensitive information disclosure vulnerability has been identified in the Code-Projects Hotel and Tourism Reservation system, specifically in the PHP version 1.0. The issue arises from an SQL database backup file, 'hotel_db (1).sql', being accessible through the web server. This vulnerability allows remote, unauthenticated attackers to retrieve the database file via an HTTP GET request, potentially exposing sensitive information such as database schema, user accounts, and reservation details.
To address this vulnerability, remove the SQL database backup file from the web root and store it in a secure location outside of the document root. Additionally, configure the web server to deny access to SQL files and ensure that production deployments do not include unnecessary development resources or installation files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 6, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | Not ApplicableVendor |
| https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Hotel%20and%20Tourism%20Reservation%20System%20%E2%80%93%20Sensitive%20Information%20Disclosure%20via%20Exposed%20SQL%20Database%20File.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-86217 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/897301 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399355 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/399355/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Code-Projects Hotel and Tourism Reservation | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 6, 2026 | New CVE Received | [email protected] |
Volerion