CVE-2025-6455: code-projects Online Hotel Reservation System messageexec.php sql injection
A vulnerability classified as critical was found in code-projects Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /messageexec.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6455?
CVE-2025-6455 is classified as a critical vulnerability due to the potential for SQL injection exploits.
How does CVE-2025-6455 impact the Online Hotel Reservation System?
CVE-2025-6455 allows attackers to manipulate the 'Name' argument in /messageexec.php, potentially compromising the database.
How can I fix CVE-2025-6455 in my application?
To fix CVE-2025-6455, sanitize and validate user inputs, particularly those used in SQL queries, to prevent SQL injection.
What versions of the Online Hotel Reservation System are affected by CVE-2025-6455?
CVE-2025-6455 affects version 1.0 of the Online Hotel Reservation System developed by code-projects.
Is there a patch available for CVE-2025-6455?
As of now, there is no official patch available for CVE-2025-6455, thus immediate remediation measures are recommended.