CVE-2025-13170

Source
https://cve.org/CVERecord?id=CVE-2025-13170
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13170.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13170
Published
2025-11-14T16:15:53.737Z
Modified
2026-03-15T22:50:13.445534Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/editaccount.php. Performing a manipulation of the argument adminid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13170.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.0"
            }
        ]
    }
]