PT-2025-46972 · Unknown · Simple Online Hotel Reservation System

Pfdlyy

·

Published

2025-11-14

·

Updated

2025-11-14

·

CVE-2025-13170

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Online Hotel Reservation System version 1.0
Description A flaw exists in the processing of the /admin/edit account.php file within the software. Manipulation of the admin id argument can lead to SQL injection. This issue is potentially exploitable remotely. The exploit is publicly available.
Recommendations Apply any available updates or patches for version 1.0. As a temporary workaround, restrict access to the /admin/edit account.php file or carefully validate the admin id argument to prevent SQL injection.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13170

Affected Products

Simple Online Hotel Reservation System