Back to overview

CVE-2026-13553

HIGH Exploitation: PoC
7.3
CVSS 3.1
Description
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.

Metadata

CVE ID
CVE-2026-13553
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-28 16:02 UTC
Published
2026-06-29 09:00 UTC
Last updated
2026-06-29 12:50 UTC
Primary CWE
CWE-434
Unrestricted Upload
Vendor / Product
itsourcecode / Online Hotel Management System
Sources
cve.org  ·  NVD

Severity & Metrics

7.3 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
itsourcecode Online Hotel Management System 1.0
Weakness (CWE)
CWESourceDescription
CWE-284 cna Improper Access Controls
CWE-434 cna Unrestricted Upload
CVSS scores (4)
ScoreSeverityVersionSourceVector
7.5 N/D 2.0 cna AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
7.3 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
7.3 HIGH 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
References (6)
Back to overview