CVE-2025-10789CRITICAL 9.8EPSS p35.0%
CVE-2025-10789CVE-2025-10789
Description
A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteslide.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.44% probability of exploitation · percentile 35.0% · 2026-06-19T12:03:05Z |
| Published | 2025-09-22 |
| Last modified | 2026-04-29 |
Underlying weaknesses· 2
References
- https://gold-textbook-8ff.notion.site/Online-Hotel-Reservation-System-In-PHP-With-Source-Code-deleteslide-php-sql-injection-26d85e97f353807585d7e600b31d339e
- https://vuldb.com/?ctiid.325146
- https://vuldb.com/?id.325146
- https://vuldb.com/?submit.653881
- https://www.sourcecodester.com/
- https://gold-textbook-8ff.notion.site/Online-Hotel-Reservation-System-In-PHP-With-Source-Code-deleteslide-php-sql-injection-26d85e97f353807585d7e600b31d339e
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-89 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.