PT-2025-41153 · Sourcecodester · Sourcecodester Hotel/Lodge Management System

Liuzhouyang

·

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-11404

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Hotel and Lodge Management System version 1.0
Description A flaw exists in SourceCodester Hotel and Lodge Management System 1.0, specifically within the /pages/save tax.php file. Manipulation of the percentage argument can result in a SQL injection. This issue is potentially exploitable remotely, and details about the exploit have been publicly disclosed.
Recommendations Apply any available updates or patches for SourceCodester Hotel and Lodge Management System version 1.0. As a temporary workaround, restrict access to the /pages/save tax.php file. Sanitize the percentage argument before using it in SQL queries.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11404

Affected Products

Sourcecodester Hotel/Lodge Management System