A vulnerability labeled as critical has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection.

This vulnerability is cataloged as CVE-2026-14756. The attack may be launched remotely. Furthermore, there is an exploit available.