📦 Online Hotel Reservation System

by Fabian

🔍 What is Online Hotel Reservation System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11055

HIGH CVSS 7.3 Sep 27, 2025

This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Online Hotel Reservation System 1.0 via the 'address' parameter in the /admin/updateaddress.php file....

CVE-2025-10843

HIGH CVSS 7.3 Sep 23, 2025

CVE-2025-10843 is an SQL injection vulnerability in Reservation Online Hotel Reservation System 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'confirm' parameter in the /r...

CVE-2025-10788

HIGH CVSS 7.3 Sep 22, 2025

This vulnerability allows remote attackers to execute SQL injection attacks on SourceCodester Online Hotel Reservation System 1.0 via the deleteroominventory.php file. Attackers can manipulate the ID ...

CVE-2025-9789

HIGH CVSS 7.3 Sep 1, 2025

This CVE describes a SQL injection vulnerability in SourceCodester Online Hotel Reservation System 1.0, specifically in the /admin/edituser.php file's userid parameter. Attackers can remotely exploit ...

CVE-2025-8469

HIGH CVSS 7.3 Aug 2, 2025

A critical SQL injection vulnerability in SourceCodester Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in /admin/deletegallery.php....

CVE-2025-6457

HIGH CVSS 7.3 Jun 22, 2025

This critical SQL injection vulnerability in code-projects Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'Start' parameter in /reservation/demo....

CVE-2025-6455

HIGH CVSS 7.3 Jun 22, 2025

A critical SQL injection vulnerability exists in code-projects Online Hotel Reservation System 1.0. Attackers can remotely exploit the /messageexec.php file by manipulating the Name parameter to execu...

CVE-2025-11353

MEDIUM CVSS 6.3 Oct 7, 2025

This vulnerability allows remote attackers to upload arbitrary files to the Online Hotel Reservation System 1.0 via the /admin/addgalleryexec.php endpoint. Attackers can potentially execute malicious ...

CVE-2025-11351

MEDIUM CVSS 6.3 Oct 7, 2025

CVE-2025-11351 is an unrestricted file upload vulnerability in code-projects Online Hotel Reservation System 1.0. Attackers can upload malicious files via the /admin/editpicexec.php endpoint, potentia...