CVE-2025-12593: code-projects Simple Online Hotel Reservation System Photo edit_room.php unrestricted upload
A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/editroom.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12593?
CVE-2025-12593 is classified as a high severity vulnerability due to the potential for unrestricted file uploads.
How do I fix CVE-2025-12593?
To mitigate CVE-2025-12593, it's advised to restrict file upload types and implement proper input validation in the Photo Handler component.
What component is affected by CVE-2025-12593?
CVE-2025-12593 affects the Photo Handler component within the Simple Online Hotel Reservation System 2.0.
What type of attack can occur due to CVE-2025-12593?
CVE-2025-12593 allows for file upload attacks, potentially leading to the execution of malicious code.
In which file is CVE-2025-12593 present?
CVE-2025-12593 is present in the /admin/edit_room.php file of the Simple Online Hotel Reservation System.