A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oretnom23
Oretnom23 resort Reservation System |
|
| CPEs | cpe:2.3:a:oretnom23:resort_reservation_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oretnom23
Oretnom23 resort Reservation System |
Mon, 09 Mar 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Title | SourceCodester/janobe Resort Reservation System controller.php doInsert unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-03-09T03:32:12.090Z
Updated: 2026-03-09T03:32:12.090Z
Reserved: 2026-03-08T12:36:53.759Z
Link: CVE-2026-3800
No data.
Status : Analyzed
Published: 2026-03-09T04:16:05.770
Modified: 2026-03-09T15:03:49.280
Link: CVE-2026-3800
No data.