PT-2025-31503 · Unknown · Campcodes Online Hotel Reservation System
Xiaojiesecqwq
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-8379
Xiaojiesecqwq
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-8379
5.8
Medium
Base vector | Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Campcodes Online Hotel Reservation System version 1.0
Description:
A critical issue exists in Campcodes Online Hotel Reservation System that allows for unrestricted file upload. The vulnerability is located in the `/admin/edit room.php` file, where manipulation of the `photo` argument enables malicious uploads. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations:
As a temporary workaround, restrict access to the `/admin/edit room.php` file to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Improper Access Control