A vulnerability classified as critical was found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads to sql injection.

This vulnerability is listed as CVE-2026-3771. The attack may be performed from remote. In addition, an exploit is available.