CVE-2018-25195

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wecodex:hotel_cms:1.0:*:*:*:*:*:*:*

History

27 Mar 2026, 21:00

Type Values Removed Values Added
First Time Wecodex
Wecodex hotel Cms
CPE cpe:2.3:a:wecodex:hotel_cms:1.0:*:*:*:*:*:*:*
Summary
  • (es) Wecodex Hotel CMS 1.0 contiene una vulnerabilidad de inyección SQL en la funcionalidad de inicio de sesión de administrador que permite a atacantes no autenticados eludir la autenticación inyectando código SQL. Los atacantes pueden enviar cargas útiles SQL maliciosas a través del parámetro de nombre de usuario en solicitudes POST a index.php con action=processlogin para extraer información sensible de la base de datos u obtener acceso administrativo no autorizado.
References () https://www.exploit-db.com/exploits/44729 - () https://www.exploit-db.com/exploits/44729 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/wecodex-hotel-cms-sql-injection-via-admin-login - () https://www.vulncheck.com/advisories/wecodex-hotel-cms-sql-injection-via-admin-login - Third Party Advisory
References () https://www.wecodex.com/item/view/hotel-management-system-in-php-and-mysql/7 - () https://www.wecodex.com/item/view/hotel-management-system-in-php-and-mysql/7 - Broken Link

26 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 12:16

Updated : 2026-03-27 21:00


NVD link : CVE-2018-25195

Mitre link : CVE-2018-25195

CVE.ORG link : CVE-2018-25195


JSON object : View

Products Affected

wecodex

  • hotel_cms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')