Critical severity9.8NVD Advisory· Published Oct 23, 2019· Updated Jun 17, 2026
CVE-2019-18387
CVE-2019-18387
Description
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
Affected products
3- cpe:2.3:a:hotel_and_lodge_management_system_project:hotel_and_lodge_management_system:1.0:*:*:*:*:*:*:*
- Sourcecodester/Hotel and Lodge Management Systemdescription
- Range: 1.0
Patches
Vulnerability mechanics
References
1- www.sevenlayers.com/index.php/266-hotel-and-lodge-management-system-1-0-sqlinvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.