CVE-2026-14764: code-projects Hotel and Tourism Reservation Event Management add_event.php sql injection
Published Jul 5, 2026
·Updated
A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/addevent.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Hotel and Tourism Reservation=1.0
Event History
Jul 5, 2026
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Oct 30, 58479
Event
via NVD·07:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-14764?
The severity of CVE-2026-14764 is high, with a score of 7.3.
2
How do I fix CVE-2026-14764?
To fix CVE-2026-14764, validate and sanitize inputs to prevent SQL injection in add_event.php.
3
What type of vulnerability is CVE-2026-14764?
CVE-2026-14764 is an SQL injection vulnerability.
4
Can CVE-2026-14764 be exploited remotely?
Yes, CVE-2026-14764 can be exploited remotely.
5
Which file is affected by CVE-2026-14764?
CVE-2026-14764 affects the file /admin/add_event.php in the Code-projects Hotel and Tourism Reservation application.