PT-2025-40961 · Code Projects · Online Hotel Reservation System

Zhicat

·

Published

2025-10-07

·

Updated

2025-10-09

·

CVE-2025-11351

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Hotel Reservation System version 1.0
Description A flaw exists in code-projects Online Hotel Reservation System 1.0 that allows for unrestricted file uploads. The issue is located in the file /admin/editpicexec.php within an unknown function, and is triggered by manipulating the image argument. Remote exploitation is possible, and the exploit has been publicly released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-11351

Affected Products

Online Hotel Reservation System