CVE-2024-25318 is a high-severity SQL Injection vulnerability affecting Code-projects Hotel Management System 1.0, specifically through the 'pid' parameter in Hotel/admin/print.php. This flaw allows an unauthenticated attacker to execute arbitrary SQL commands, potentially leading to full compromise of the database and sensitive data. With a CVSS score of 8.8, the vulnerability is easily exploitable over the network with low attack complexity, posing a significant risk of high impact to confidentiality, integrity, and availability. While there is currently no evidence of active exploitation, nor are public exploit tools like Metasploit or ExploitDB modules available, the low EPSS score and lack of community discussion suggest it is not widely known or targeted at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:hotel_management_system_project:hotel_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.