CVE-2025-6450: code-projects Simple Online Hotel Reservation System confirm_reserve.php sql injection
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/confirmreserve.php. The manipulation of the argument transactionid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6450?
CVE-2025-6450 has been classified as critical.
What part of the software is affected by CVE-2025-6450?
CVE-2025-6450 affects the /admin/confirm_reserve.php file.
What type of vulnerability is CVE-2025-6450?
CVE-2025-6450 is a SQL injection vulnerability caused by manipulation of the transaction_id argument.
How do I fix CVE-2025-6450?
To fix CVE-2025-6450, ensure that user input is properly sanitized and validated before being used in SQL queries.
What software versions are impacted by CVE-2025-6450?
CVE-2025-6450 specifically affects version 1.0 of the Simple Online Hotel Reservation System.