SourceCodester Hotel and Lodge Management System是SourceCodester开源的一套酒店和旅馆管理系统。 SourceCodester Hotel and Lodge Management System 1.0及之前版本存在代码问题漏洞,该漏洞源于对文件/manage_website.php中参数website_image/back_login_image的错误操作,可能导致任意文件上传。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Hotel and Lodge Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-11480 | 7.3 HIGH | SourceCodester Simple E-Commerce Bookstore register.php sql injection |
| CVE-2025-11479 | 7.3 HIGH | SourceCodester Wedding Reservation Management System function.php insertReservation sql in |
| CVE-2025-11477 | 7.3 HIGH | SourceCodester Wedding Reservation Management System global.php sql injection |
| CVE-2025-11476 | 7.3 HIGH | SourceCodester Simple E-Commerce Bookstore index.php sql injection |
| CVE-2025-11473 | 7.3 HIGH | SourceCodester Hotel and Lodge Management System edit_curr.php sql injection |
| CVE-2025-11472 | 7.3 HIGH | SourceCodester Hotel and Lodge Management System edit_room.php sql injection |
| CVE-2025-11471 | 7.3 HIGH | SourceCodester Hotel and Lodge Management System edit_customer.php sql injection |
| CVE-2025-11430 | 7.3 HIGH | SourceCodester Simple E-Commerce Bookstore cart.php sql injection |
| CVE-2025-11487 | 6.3 MEDIUM | SourceCodester Farm Management System uploadProduct.php sql injection |
| CVE-2025-11486 | 6.3 MEDIUM | SourceCodester Farm Management System buyNow.php sql injection |
| CVE-2025-11478 | 6.3 MEDIUM | SourceCodester Farm Management System myCart.php sql injection |
| CVE-2025-11474 | 6.3 MEDIUM | SourceCodester Hotel and Lodge Management System edit_booking.php sql injection |
| CVE-2025-11469 | 6.3 MEDIUM | SourceCodester Hotel and Lodge Management System save_customer.php sql injection |
| CVE-2025-11485 | 2.4 LOW | SourceCodester Student Grades Management System Manage Users admin.php add_user cross site |
No comments yet