PT-2025-47060 · Unknown · Fantasticlbp Hotels Server

Naixiao

·

Published

2025-11-15

·

Updated

2025-11-15

·

CVE-2025-13208

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FantasticLBP Hotels Server versions prior to 67b44df162fab26df209bd5d5d542875fcbec1d0
Description A security flaw exists in FantasticLBP Hotels Server. The issue involves a SQL injection that can be triggered by manipulating the subjectId/cityName argument within an unknown function in the file controller/api/hotelList.php. This allows for remote execution of attacks. The exploit has been publicly released.
Recommendations Versions prior to 67b44df162fab26df209bd5d5d542875fcbec1d0 should be updated. As a temporary workaround, restrict or avoid using the subjectId/cityName parameters in the /api/hotelList.php endpoint.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-13208

Affected Products

Fantasticlbp Hotels Server