A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
History

Wed, 05 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Fabian
Fabian simple Online Hotel Reservation System
CPEs cpe:2.3:a:fabian:simple_online_hotel_reservation_system:2.0:*:*:*:*:*:*:*
Vendors & Products Fabian
Fabian simple Online Hotel Reservation System

Mon, 03 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects simple Online Hotel Reservation System
Vendors & Products Code-projects
Code-projects simple Online Hotel Reservation System

Sun, 02 Nov 2025 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Title code-projects Simple Online Hotel Reservation System Photo edit_room.php unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-02T06:02:05.981Z

Updated: 2025-11-03T15:43:16.030Z

Reserved: 2025-11-01T15:57:22.011Z

Link: CVE-2025-12593

cve-icon Vulnrichment

Updated: 2025-11-03T15:43:11.185Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-02T05:15:32.777

Modified: 2025-11-05T19:01:39.847

Link: CVE-2025-12593

cve-icon Redhat

No data.