VYPR
Vendor

Hotel Management System Project

Products
1
CVEs
12
Across products
12
Status
Private

Products

1

Recent CVEs

12
  • CVE-2024-25316CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

  • CVE-2024-25315CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

  • CVE-2024-25314CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.

  • CVE-2022-28110CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.

  • CVE-2024-25318HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.

  • CVE-2021-41651HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.02

    A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.

  • CVE-2022-48090MedJan 13, 2023
    risk 0.42cvss 6.5epss 0.01

    Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.

  • CVE-2022-48091MedJan 13, 2023
    risk 0.35cvss 5.4epss 0.00

    Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.

  • CVE-2022-36254MedSep 12, 2022
    risk 0.35cvss 5.4epss 0.01

    Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".

  • CVE-2022-2291MedJul 12, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the input…

  • CVE-2022-2292LowJul 12, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown function of the file /ci_hms/massage_room/edit/1 of the component Room Edit Page. The manipulation of the argument massageroomDetails with the input…

  • CVE-2022-27475MedApr 13, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.