📦 Hotel And Lodge Management System

by Nikhil Bhalerao

🔍 What is Hotel And Lodge Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11471

HIGH CVSS 7.3 Oct 8, 2025

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to manipulate database queries through the /edit_customer.php file's ID parameter. Attackers c...

CVE-2025-11473

HIGH CVSS 7.3 Oct 8, 2025

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'currsymbol' parameter in the /edit_curr.php file of SourceCodester Hotel and Lodge Management System 1.0. This can...

CVE-2025-11397

HIGH CVSS 7.3 Oct 7, 2025

An SQL injection vulnerability exists in SourceCodester Hotel and Lodge Management System 1.0's login.php file via the email parameter. This allows remote attackers to execute arbitrary SQL commands, ...

CVE-2025-11469

MEDIUM CVSS 6.3 Oct 8, 2025

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to manipulate database queries through the Contact parameter in /pages/save_customer.php. Atta...

CVE-2025-11470

MEDIUM CVSS 4.7 Oct 8, 2025

This vulnerability allows attackers to upload arbitrary files to the Hotel and Lodge Management System through the /manage_website.php endpoint. Attackers can exploit this remotely to upload malicious...

CVE-2025-11405

MEDIUM CVSS 6.3 Oct 7, 2025

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to manipulate database queries through the /del_tax.php file's ID parameter. Attackers can pot...

CVE-2025-11402

MEDIUM CVSS 6.3 Oct 7, 2025

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /del_curr.php file of SourceCodester Hotel and Lodge Management System 1.0, potentially leading...

CVE-2025-11403

MEDIUM CVSS 6.3 Oct 7, 2025

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows remote attackers to manipulate database queries via the /del_booking.php file. Attackers could potential...

CVE-2025-11401

MEDIUM CVSS 6.3 Oct 7, 2025

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'currcode' parameter in the /pages/save_curr.php file of SourceCodester Hotel and Lodge Management System 1.0. This...

CVE-2025-11399

MEDIUM CVSS 6.3 Oct 7, 2025

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to manipulate database queries through the 'floorno' parameter in /pages/save_room.php. Remote...

CVE-2025-11400

MEDIUM CVSS 6.3 Oct 7, 2025

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter in /del_room.php. Attackers can potenti...

CVE-2025-11398

MEDIUM CVSS 6.3 Oct 7, 2025

SourceCodester Hotel and Lodge Management System 1.0 has an unrestricted file upload vulnerability in the profile.php image upload function. Attackers can remotely upload malicious files, potentially ...