A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function of the file /manage_website.php. The manipulation of the argument website_image/back_login_image leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
2025-10-08T10:15:37.427
2025-10-08T20:49:10.957
Analyzed
CVSSv3.1: 4.7 (MEDIUM)
AV:N/AC:L/Au:M/C:P/I:P/A:P
6.4
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nikhil-bhalerao | hotel_and_lodge_management_system | 1.0 | Yes |