CVE-2025-13170: code-projects Simple Online Hotel Reservation System edit_account.php sql injection
A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/editaccount.php. Performing a manipulation of the argument adminid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13170?
CVE-2025-13170 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2025-13170?
To fix CVE-2025-13170, sanitize and validate all user inputs, especially the admin_id parameter in the edit_account.php file.
What systems are affected by CVE-2025-13170?
CVE-2025-13170 affects Code-projects Simple Online Hotel Reservation System version 1.0.
Can CVE-2025-13170 lead to data breaches?
Yes, CVE-2025-13170 can lead to unauthorized access to the database, potentially resulting in data breaches.
Is there a known exploit for CVE-2025-13170?
Yes, there are known exploits that can leverage the SQL injection vulnerability in CVE-2025-13170.