5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this issue is some unknown functionality of the file /del_booking.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Basic Information
ID
CVE-2025-11403
Source
VulDB
Published
Oct 7, 2025 at 18:02
Modified
Oct 7, 2025 at 18:26
Affected Product
Vendor
SourceCodester
Product
Hotel and Lodge Management System
Version
1.0
Affected Versions
SourceCodester Hotel and Lodge Management System 1.0