<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-4612 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-4612/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 24 Mar 2026 14:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-4612/feed.xml" rel="self" type="application/rss+xml"/><item><title>SQL Injection Vulnerability in Free Hotel Reservation System 1.0</title><link>https://feed.craftedsignal.io/briefs/2026-03-hotel-reservation-sqli/</link><pubDate>Tue, 24 Mar 2026 14:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-hotel-reservation-sqli/</guid><description>A SQL injection vulnerability (CVE-2026-4612) exists in itsourcecode Free Hotel Reservation System 1.0 within the Parameter Handler component, allowing remote attackers to execute arbitrary SQL commands via the account_id parameter in the /hotel/admin/mod_users/index.php script.</description><content:encoded><![CDATA[<p>The itsourcecode Free Hotel Reservation System 1.0 is vulnerable to SQL injection (CVE-2026-4612). The vulnerability resides in the Parameter Handler component, specifically affecting the <code>/hotel/admin/mod_users/index.php</code> script. By manipulating the <code>account_id</code> parameter, a remote attacker can inject arbitrary SQL commands into the application&rsquo;s database queries. The vulnerability was reported in March 2026 and has a CVSS v3.1 score of 7.3 (HIGH). Publicly available exploit code increases the…</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-4612</category><category>sql-injection</category><category>web-application</category></item></channel></rss>