CVE-2026-2553
Last modified
CVE-2026-2553 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown part of the file /home.php of the component HTTP POST Request Handler. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown part of the file /home.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Name/Email results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-2553?
How severe is CVE-2026-2553?
How do I fix CVE-2026-2553?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25524Magento Long Term Support (LTS) is an unofficial, community-…8.1
- CVE-2026-25525Magento Long Term Support (LTS) is an unofficial, community-…4.9
- CVE-2026-25526JinJava is a Java-based template engine based on django temp…9.8
- CVE-2026-25527changedetection.io is a free open source web page change det…5.3
- CVE-2026-25528LangSmith Client SDKs provide SDK's for interacting with the…5.8
- CVE-2026-25529Postal is an open source SMTP server. Postal versions less t…8.1
- CVE-2026-25530Kanboard is project management software focused on Kanban me…4.3
- CVE-2026-25531Kanboard is project management software focused on Kanban me…4.3
- CVE-2026-25532ESF-IDF is the Espressif Internet of Things (IOT) Developmen…8
- CVE-2026-25533Enclave is a secure JavaScript sandbox designed for safe AI …8.8
- CVE-2026-25534### Impact Spinnaker updated URL Validation logic on user in…9.1
- CVE-2026-25535jsPDF is a library to generate PDFs in JavaScript. Prior to …7.5
Are you affected by CVE-2026-2553?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
