CVE-2025-7606: code-projects AVL Rooms city.php sql injection
Published Jul 14, 2025
·Updated
A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of the argument city leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects AVL Rooms
Anisha Avl Rooms=1.0
Event History
Jul 14, 2025
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 21, 58473
Event
via NVD·09:38 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-7606?
CVE-2025-7606 is classified as a critical vulnerability.
2
How does CVE-2025-7606 affect the AVL Rooms software?
CVE-2025-7606 affects the city.php file in AVL Rooms, leading to a potential SQL injection.
3
Can CVE-2025-7606 be exploited remotely?
Yes, CVE-2025-7606 can be exploited remotely.
4
What is the primary cause of CVE-2025-7606?
The primary cause of CVE-2025-7606 is the manipulation of the 'city' argument.
5
How can I fix CVE-2025-7606 in AVL Rooms?
To fix CVE-2025-7606, validate and sanitize all user inputs to prevent malicious SQL injection.