---
id: CVE-2025-10621
title: A vulnerability was determined in SourceCodester Hotel Reservation System 1.0
summary: >-
  A vulnerability was determined in SourceCodester Hotel Reservation System 1.0.
  The affected element is an unknown function of the file editroomimage.php.
  This manipulation of the argument ID causes sql injection. It is possible to
  initia…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: fabian
product: hotel_reservation_system
affected:
  - hotel_reservation_system = 1.0
published: '2025-09-17'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10621'
references:
  - url: 'https://github.com/aCas1o/cve_report/blob/main/report.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.324650'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.324650'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.650218'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
  - url: 'https://github.com/aCas1o/cve_report/blob/main/report.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00478
epssPercentile: 0.38793
ingestedAt: '2026-09-26T00:22:39.945Z'
---

## Overview

A vulnerability was determined in SourceCodester Hotel Reservation System 1.0. The affected element is an unknown function of the file editroomimage.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

## Affected

- `hotel_reservation_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
