CVE-2025-11352: code-projects Online Hotel Reservation System addexec.php unrestricted upload
A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown function of the file /admin/addexec.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11352?
CVE-2025-11352 is classified with a high severity due to the potential for unrestricted file uploads.
How do I fix CVE-2025-11352?
To fix CVE-2025-11352, implement proper input validation and restrict the types of files that can be uploaded in the /admin/addexec.php file.
What type of vulnerability is CVE-2025-11352?
CVE-2025-11352 is a vulnerability that allows for unrestricted file uploads, which can lead to remote code execution.
Can CVE-2025-11352 be exploited remotely?
Yes, CVE-2025-11352 can be exploited remotely due to the nature of the vulnerability in the affected software.
What software is affected by CVE-2025-11352?
CVE-2025-11352 affects the Online Hotel Reservation System version 1.0 developed by code-projects.