CVE-2026-86217
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 06, 2026
Vendor
unknown
Description
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.
References
- https://code-projects.org/
- https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Hotel%20and%20Tourism%20Reservation%20System%20%E2%80%93%20Sensitive%20Information%20Disclosure%20via%20Exposed%20SQL%20Database%20File.md
- https://vuldb.com/cve/CVE-2026-86217
- https://vuldb.com/submit/897301
- https://vuldb.com/vuln/399355