CVE-2025-11470
Published
CVSS v3
4.7
MEDIUM
CVSS v2
5.8
MEDIUM
Affected
1
PROJECT
Description
A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function of the file /manage_website.php. The manipulation of the argument website_image/back_login_image leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.