PT-2025-41011 · Sourcecodester · Sourcecodester Hotel/Lodge Management System

Tthuyyy

·

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-11398

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Hotel and Lodge Management System version 1.0
Description A flaw exists in SourceCodester Hotel and Lodge Management System 1.0 that allows for unrestricted file upload. This is due to manipulation of the image argument within an unknown function of the /profile.php file, part of the Profile Page component. The exploit is publicly available and can be launched remotely.
Recommendations Apply any available updates or patches for SourceCodester Hotel and Lodge Management System version 1.0. As a temporary workaround, restrict access to the /profile.php file. Avoid uploading any untrusted files through the Profile Page component.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-11398

Affected Products

Sourcecodester Hotel/Lodge Management System