code-projects Hotel and Tourism Reservation Event Management add_event.php sql injection
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
code-projects · Hotel and Tourism Reservationpublic PoCs found — 1
cve_referenceraw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Hotel-Tourism-Reservation-add_event.php_SQLi.mdunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.