PT-2025-41268 · Sourcecodester · Wedding Reservation Management System

Drnbnonono

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-11479

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Wedding Reservation Management System version 1.0
Description A security issue exists in the Wedding Reservation Management System. The insertReservation function within the function.php file is susceptible to SQL injection due to manipulation of the number argument. This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11479

Affected Products

Wedding Reservation Management System