CVE Feed

    Dashboard / CVE / CVE-2018-25195

    CVE-2018-25195

    Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.

    Published:Mar 26, 2026
    Last Modified:Mar 29, 2026
    EPS:Mar 26, 2026
    EPSS Score:0.00332
    CVSS Score:8.2

    Affected Products

    Vendor
    Wecodex
    Product
    Hotel Cms
    Vendor
    Wecodex
    Product
    Wecodex Hotel Cms

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High