A vulnerability, which was classified as critical, has been found in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit&id=9. Performing a manipulation of the argument amen_id results in sql injection.
This vulnerability is reported as CVE-2026-3730. The attack is possible to be carried out remotely. Moreover, an exploit is present.