A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Title | SourceCodester/janobe Resort Reservation System controller.php doInsert unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-09T03:32:12.090Z
Reserved: 2026-03-08T12:36:53.759Z
Link: CVE-2026-3800
No data.
Status : Received
Published: 2026-03-09T04:16:05.770
Modified: 2026-03-09T04:16:05.770
Link: CVE-2026-3800
No data.
OpenCVE Enrichment
No data.