Description
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Problem types
Product status
Timeline
| 2026-03-08: | Advisory disclosed |
| 2026-03-08: | VulDB entry created |
| 2026-03-08: | VulDB entry last update |
Credits
webray.com.cn (VulDB User)
References
vuldb.com/?id.349767 (VDB-349767 | SourceCodester/janobe Resort Reservation System controller.php doInsert unrestricted upload)
vuldb.com/?ctiid.349767 (VDB-349767 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.768978 (Submit #768978 | janobe Resort Reservation System 1.0 Unrestricted Upload)
vuldb.com/?submit.768998 (Submit #768998 | janobe Resort Reservation System 1.0 Unrestricted Upload (Duplicate))
github.com/...rt-Reservation-System---Unrestricted-Upload.md