Impact
The vulnerability allows an attacker to manipulate the password argument in the password_verify function within the admin login page, enabling successful authentication without a valid credential. This flaw falls under CWE‑287 and permits an attacker to bypass authentication controls. The reported exploit is publicly available, indicating that the flaw is known and can be reproduced by remote actors.
Affected Systems
code‑projects Hotel and Tourism Reservation System version 1.0 contains the affected component. No other products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as medium severity. Although the EPSS score is not provided, the public availability of the exploit suggests that the attack is feasible. The vulnerability can be reached through the web interface, and no special privileges are required to obtain unauthorized administrator access. The flaw is not present in CISA’s KEV catalog, but the potential impact on administrative functionality warrants attention.
OpenCVE Enrichment