CVE-2026-14756: code-projects Hotel and Tourism Reservation Tour Management add_tour.php sql injection
A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/addtour.php of the component Tour Management Page. The manipulation of the argument deleteimage results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14756?
The severity of CVE-2026-14756 is rated as high with a score of 7.3.
What type of vulnerability is CVE-2026-14756?
CVE-2026-14756 is a SQL Injection vulnerability affecting the add_tour.php file.
How do I fix CVE-2026-14756?
To fix CVE-2026-14756, sanitize and validate all user inputs to prevent SQL injection.
What component is affected by CVE-2026-14756?
CVE-2026-14756 affects the Tour Management Page of the Code-projects Hotel and Tourism Reservation software.
Can CVE-2026-14756 be exploited remotely?
Yes, CVE-2026-14756 can be exploited remotely as it allows attackers to manipulate SQL queries.