CVE-2025-10623: SourceCodester Hotel Reservation System deleteuser.php sql injection
A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10623?
CVE-2025-10623 has a high severity rating due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-10623?
To fix CVE-2025-10623, sanitize and validate all input for the deleteuser.php function and implement prepared statements for database queries.
Can CVE-2025-10623 be exploited remotely?
Yes, CVE-2025-10623 can be exploited remotely by manipulating the ID argument in the deleteuser.php file.
What software is affected by CVE-2025-10623?
CVE-2025-10623 affects SourceCodester Hotel Reservation System version 1.0.
What are the potential consequences of CVE-2025-10623?
Exploitation of CVE-2025-10623 can lead to unauthorized access to the database, data manipulation, and compromise of sensitive information.