PT-2025-44731 · Code Projects · Simple Online Hotel Reservation System

Yunlin

·

Published

2025-11-02

·

Updated

2025-11-02

·

CVE-2025-12593

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Simple Online Hotel Reservation System version 2.0
Description A flaw exists in code-projects Simple Online Hotel Reservation System 2.0 that allows for unrestricted file uploads. This issue is located within the Photo Handler component, specifically in the /admin/edit room.php file and an unknown function. The attack can be initiated remotely. An exploit for this issue is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12593

Affected Products

Simple Online Hotel Reservation System