Impact
A vulnerability exists in the admin login component of itsourcecode Online Hotel Management System 1.0. An attacker who supplies a crafted email value to /admin/login.php can inject arbitrary SQL sentences, potentially reading, modifying, or deleting database data. The flaw is manifested through CWE-74 and CWE-89 weaknesses.
Affected Systems
The vulnerability affects itsourcecode Online Hotel Management System version 1 affected in the CVE data.
Risk and Exploitability
The CVSS score of 6.9 denotes medium severity, while the EPSS score of <1 chance at present. The vulnerability is not listed in CISA KEV, but public exploit code is available and the attack can be launched over the network. Operators should treat the exposure as a concern, particularly if the application is accessible from the internet.
OpenCVE Enrichment