SQL Injection Vulnerability in SourceCodester Online Hotel Reservation System
CVE-2025-6355
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 20 June 2025
Badges
What is CVE-2025-6355?
A SQL injection vulnerability exists in the SourceCodester Online Hotel Reservation System 1.0. This security flaw affects the /admin/execeditroom.php file, allowing remote attackers to manipulate the 'userid' argument. Successful exploitation can lead to unauthorized access and potential data breaches. Given its public disclosure, it is crucial for users to take immediate action to mitigate the risks associated with this vulnerability.
Affected Version(s)
Online Hotel Reservation System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved