CVE-2026-86217CWE-200CWE-284

code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure

Medium · published September 6, 2026

CVSS v3.1
5.3
EPSS
In the wild
Unconfirmed
What it is

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
CVSS v4.0
6.9 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
Not scored
Weaknesses
CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor; CWE-284 · Improper Access Control
Published
2026-09-06T14:30Z
Timeline
  • 06 SEP 14:30Z
    code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure
    cvelistv5