PT-2024-37392 · Unknown · Simple Online Hotel Reservation System

Wangyuan-Ui

·

Published

2024-06-18

·

Updated

2026-02-18

·

CVE-2024-6115

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Simple Online Hotel Reservation System version 1.0
Description: A critical vulnerability was found in the Simple Online Hotel Reservation System, affecting an unknown functionality of the file add room.php. The manipulation of the photo argument leads to unrestricted upload. The attack can be launched remotely.
Recommendations: For Simple Online Hotel Reservation System version 1.0, consider disabling the add room.php file or restricting access to it until a patch is available to prevent unrestricted upload. Avoid using the photo argument in the affected file until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-6115

Affected Products

Simple Online Hotel Reservation System