{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acode_projectshotel_and_tourism_reservation_1_0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:code_projects:hotel_and_tourism_reservation_1_0:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-14762"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-TC4DY-CVE-2026-14762-POC-EXPLOIT\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Hotel and Tourism Reservation 1.0"],"_cs_severities":["high"],"_cs_tags":["sql-injection","web-application","cve","php"],"_cs_type":"advisory","_cs_vendors":["code-projects"],"content_html":"\u003cp\u003eA significant vulnerability, identified as CVE-2026-14762, has been discovered in code-projects Hotel and Tourism Reservation version 1.0. This flaw specifically impacts an unspecified function within the \u003ccode\u003e/admin/rooms.php\u003c/code\u003e file, part of the application's Room Management Page. Attackers can exploit this vulnerability by manipulating the \u003ccode\u003edelete\u003c/code\u003e argument with SQL injection payloads. This issue is remotely exploitable, meaning an attacker does not require local access to the affected system. The exploit code for CVE-2026-14762 is publicly available, increasing the urgency for immediate mitigation by organizations utilizing this software. Successful exploitation can lead to unauthorized access, modification, or deletion of database contents, potentially compromising sensitive customer or reservation data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a vulnerable instance of code-projects Hotel and Tourism Reservation 1.0 exposed to the internet.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting the \u003ccode\u003e/admin/rooms.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a specially crafted SQL injection payload within the \u003ccode\u003edelete\u003c/code\u003e argument, bypassing input sanitization (e.g., \u003ccode\u003eGET /admin/rooms.php?delete=' OR 1=1--\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe vulnerable PHP application processes the request and concatenates the malicious \u003ccode\u003edelete\u003c/code\u003e argument value directly into an SQL query.\u003c/li\u003e\n\u003cli\u003eThe backend database executes the attacker-controlled SQL query, treating the payload as legitimate SQL code.\u003c/li\u003e\n\u003cli\u003eDepending on the payload, the database may return sensitive information, allow data modification/deletion, or enable further database compromise.\u003c/li\u003e\n\u003cli\u003eThe application returns the result of the arbitrary SQL query to the attacker via the HTTP response.\u003c/li\u003e\n\u003cli\u003eAttacker achieves unauthorized access to, or modification of, the application's underlying database, potentially leading to full data compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14762 grants attackers unauthorized access to the application's database. This can lead to the exfiltration of sensitive information, such as customer details, reservation data, or administrator credentials. Attackers could also modify or delete critical operational data, causing service disruption or data integrity issues. Given that the exploit is public, organizations using Hotel and Tourism Reservation 1.0 are at immediate and severe risk of data breaches and operational downtime. The CVSS v3.1 score of 7.3 (HIGH) reflects the potential for significant impact on confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-14762 by updating code-projects Hotel and Tourism Reservation 1.0 to a secure version as soon as a fix is available from the vendor.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules in this brief to your SIEM and tune for your environment to detect exploitation attempts.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to inspect and block malicious HTTP requests containing SQL injection payloads targeting \u003ccode\u003e/admin/rooms.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRegularly review web server access logs for suspicious requests to \u003ccode\u003e/admin/rooms.php\u003c/code\u003e that include uncommon characters or SQL keywords in the query parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T21:18:41Z","date_published":"2026-07-05T16:20:55Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14762-sql-injection/","summary":"A critical SQL injection vulnerability (CVE-2026-14762) exists in code-projects Hotel and Tourism Reservation version 1.0, located in the `/admin/rooms.php` file's Room Management Page, allowing remote attackers to manipulate the `delete` argument for data compromise, with a public exploit now available.","title":"CVE-2026-14762: Remote SQL Injection in code-projects Hotel and Tourism Reservation","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14762-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:code_projects:hotel_and_tourism_reservation_1_0:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}