CVE-2025-1965: projectworlds Online Hotel Booking login.php sql injection
A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1965?
CVE-2025-1965 is classified as a critical vulnerability due to its potential for remote exploitation.
How does CVE-2025-1965 affect the Online Hotel Booking application?
CVE-2025-1965 affects the Online Hotel Booking application by allowing SQL injection through the /admin/login.php file.
How do I fix CVE-2025-1965?
To fix CVE-2025-1965, you should sanitize user inputs in the emailusername parameter to prevent SQL injection.
Can CVE-2025-1965 be exploited remotely?
Yes, CVE-2025-1965 can be exploited remotely by manipulating the emailusername parameter.
Which version of Online Hotel Booking is affected by CVE-2025-1965?
CVE-2025-1965 affects version 1.0 of the projectworlds Online Hotel Booking application.