CVE-2025-11404 PUBLISHED

SourceCodester Hotel and Lodge Management System save_tax.php sql injection

Assigner: VulDB
Reserved: 07.10.2025 Published: 07.10.2025 Updated: 07.10.2025

A vulnerability was determined in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown part of the file /pages/save_tax.php. Executing manipulation of the argument percentage can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor SourceCodester
Product Hotel and Lodge Management System
Versions
  • Version 1.0 is affected

Credits

  • liuzhouyang (VulDB User) reporter

References

Problem Types

  • SQL Injection CWE
  • Injection CWE