CVE-2025-11055: SourceCodester Online Hotel Reservation System updateaddress.php sql injection
A vulnerability was detected in SourceCodester Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/updateaddress.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11055?
CVE-2025-11055 is considered a high severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-11055?
To fix CVE-2025-11055, input validation and sanitization should be implemented in the affected function in updateaddress.php.
What systems are affected by CVE-2025-11055?
CVE-2025-11055 affects version 1.0 of the SourceCodester Online Hotel Reservation System.
Can CVE-2025-11055 be exploited remotely?
Yes, CVE-2025-11055 can be exploited remotely through SQL injection.
What function is vulnerable in CVE-2025-11055?
The vulnerable function in CVE-2025-11055 is located in the file /admin/updateaddress.php.