Severity
5.3MEDIUM
EPSS
0.0%
top 87.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9
Latest updateMar 10

Description

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-q5gc-m94w-rw4r: A vulnerability has been found in SourceCodester/janobe Resort Reservation System 12026-03-09
CVEList
SourceCodester/janobe Resort Reservation System controller.php doInsert unrestricted upload2026-03-09

📋Vendor Advisories

13
Microsoft
Chromium: CVE-2026-3545 Insufficient data validation in Navigation2026-03-10
Microsoft
Chromium: CVE-2026-3539 Object lifecycle issue in DevTools2026-03-10
Microsoft
Chromium: CVE-2026-3542 Inappropriate implementation in WebAssembly2026-03-10
Microsoft
Chromium: CVE-2026-3543 Inappropriate implementation in V82026-03-10
Microsoft
Chromium: CVE-2026-3538 Integer overflow in Skia2026-03-10