CVE-2026-3730Disclosure(itsourcecode / free_hotel_reservation_system)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performing a manipulation of the argument amen_id/rmtype_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free_hotel_reservation_system

Threat summary

  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-08); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Products
free_hotel_reservation_system

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-08: 4Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-08: 2Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0803-0903-1203-13
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-084
Disclosure3General1
2026-03-091
Disclosure1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse7 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3730 SQL Injection in itsourcecode Free Hotel Reservation System 1.0 via Amenities Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3730

    Post summary

    CVE-2026-3730 is an SQL injection vulnerability in the Amenities module of the Free Hotel Reservation System 1.0, as documented on vulmon.com.

    0001058
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3730 (CVSS:6.9, HIGH) is Analyzed. A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknow..https://nvd.nist.gov/vuln/detail/CVE-2026-3730 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A vulnerability with CVSS 6.9 was reported in Free Hotel Reservation System 1.0, with a link to the NVD entry for more details.

    0000016
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3730 (CVSS:6.9, HIGH) is Analyzed. A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknow..https://nvd.nist.gov/vuln/detail/CVE-2026-3730 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3730 with a CVSS score of 6.9 against the Free Hotel Reservation System 1.0, providing basic vulnerability details but no evidence of exploitation, PoC, or patch information.

    0000016
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 itsourcecode Free Hotel Reservation System, SQL Injection, #CVE-2026-3730 (Medium) https://dailycve.com/itsourcecode-free-hotel-reservation-system-sql-injection-cve-2026-3730-medium/

    Post summary

    The tweet announces a medium‑severity SQL injection vulnerability (CVE‑2026‑3730) discovered in the itsourcecode Free Hotel Reservation System and provides a link to a CVE report.

    0000037
    166 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3730 A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenitie… https://www.cve.org/CVERecord?id=CVE-2026-3730

    Post summary

    A brief disclosure of CVE-2026-3730 affecting Free Hotel Reservation System 1.0, with a reference link to the CVE record.

    0000097
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3730 - itsourcecode - Free Hotel Reservation System - https://www.redpacketsecurity.com/cve-alert-cve-2026-3730-itsourcecode-free-hotel-reservation-system/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3730 #itsourcecode #free-hotel-reservation-system

    Post summary

    The post announces CVE‑2026‑3730 for the itsourcecode Free Hotel Reservation System, pointing to an external link but providing no technical, PoC, or exploitation details.

    00000113
    3.5K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3730 - itsourcecode Free Hotel Reservation System index.php sql injection Intel Report: https://ift.tt/iZF3nqV

    Post summary

    The alert reports a CVE-2026-3730 SQL injection in the index.php of itsourcecode Free Hotel Reservation System, but offers no PoC, exploit, remediation, or activity details.

    0000034
    347 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appitsourcecodefree_hotel_reservation_system1.0--

Explore more