First published: Tue Mar 04 2025(Updated: )
A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. The manipulation of the argument roomname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Online Hotel Booking | ||
Projectworlds Online Hotel Booking | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1962 has been classified as a critical vulnerability.
CVE-2025-1962 is associated with an SQL injection vulnerability in the module /admin/addroom.php of Projectworlds Online Hotel Booking 1.0.
The vulnerability can be exploited by manipulating the 'roomname' argument, leading to SQL injection attacks.
Yes, CVE-2025-1962 can be initiated remotely, allowing attackers to exploit the vulnerability from anywhere.
To fix CVE-2025-1962, ensure proper input validation and sanitization for the 'roomname' parameter in the affected file.