Impact
The login routine of Wecodex Hotel CMS 1.0 permits an attacker to inject arbitrary SQL code through the username field sent in a POST request to index.php?action=processlogin. This flaw allows unauthenticated users to bypass authentication, elevate privileges to the administrative interface, and potentially retrieve or modify sensitive data. The weakness aligns with the common SQL injection category identified by CWE-89.
Affected Systems
Only installations of Wecodex Hotel CMS version 1.0 are known to suffer from this vulnerability; no other versions are reported as affected.
Risk and Exploitability
The base CVSS score of 8.8 demonstrates a high‑severity risk. No EPSS score is available. Exploitation can occur remotely over the public web interface without any prior authentication and requires only network access to the server. Although it is not included in CISA's catalog of known exploited vulnerabilities, the attack could compromise confidentiality, integrity, and availability of the system.
OpenCVE Enrichment