CVE-2025-8469: SourceCodester Online Hotel Reservation System deletegallery.php sql injection
A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8469?
CVE-2025-8469 is classified as a critical vulnerability.
How does CVE-2025-8469 affect the Online Hotel Reservation System?
CVE-2025-8469 affects the /admin/deletegallery.php file, leading to SQL injection attacks.
Can CVE-2025-8469 be exploited remotely?
Yes, CVE-2025-8469 can be initiated by an attacker remotely.
What part of the Online Hotel Reservation System is vulnerable due to CVE-2025-8469?
The vulnerability in CVE-2025-8469 is associated with the ID argument manipulation in the /admin/deletegallery.php file.
How do I fix CVE-2025-8469?
Fixing CVE-2025-8469 requires sanitizing input for the ID argument to prevent SQL injection.