A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing manipulation of the argument admin_id results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 15 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects simple Online Hotel Reservation System
Vendors & Products Code-projects
Code-projects simple Online Hotel Reservation System

Fri, 14 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing manipulation of the argument admin_id results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title code-projects Simple Online Hotel Reservation System edit_account.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-11-14T16:24:19.569Z

Reserved: 2025-11-14T08:17:10.479Z

Link: CVE-2025-13170

cve-icon Vulnrichment

Updated: 2025-11-14T16:24:03.174Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-14T16:15:53.737

Modified: 2025-11-14T16:42:03.187

Link: CVE-2025-13170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-15T21:25:27Z