Impact
A flaw exists in the /admin/reservations.php page of Code‑Projects Hotel and Tourism Reservation 1.0 that allows a malicious actor to inject arbitrary SQL through the delete parameter. The injection could give an attacker the ability to read, modify, or delete reservation records, potentially compromising data integrity and confidentiality.
Affected Systems
The vulnerability affects deployments of Code‑Projects Hotel and Tourism Reservation version 1.0 that expose the /admin/reservations.php endpoint and provide a delete functionality for reservation records. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and the EPSS score of less than 1 % suggests a low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. It can be triggered remotely via the delete parameter on the reservations.php page. The description does not state whether authentication is required, so it is unclear if the flaw can be exploited by unauthenticated or only authenticated users.
OpenCVE Enrichment