CVE-2025-6159: code-projects Hostel Management System allocate_room.php sql injection
A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /allocateroom.php. The manipulation of the argument searchbox leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6159?
CVE-2025-6159 is classified as a critical vulnerability that allows SQL injection.
How do I fix CVE-2025-6159?
To fix CVE-2025-6159, validate and sanitize all user inputs in the /allocate_room.php file.
What impact does CVE-2025-6159 have on the Hostel Management System?
CVE-2025-6159 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
Is CVE-2025-6159 exploitable remotely?
Yes, CVE-2025-6159 can be exploited remotely by manipulating the search_box parameter.
Which version of the Hostel Management System is affected by CVE-2025-6159?
CVE-2025-6159 affects the Code-projects Hostel Management System version 1.0.