---
id: CVE-2025-10623
title: A vulnerability was identified in SourceCodester Hotel Reservation System 1.0
summary: >-
  A vulnerability was identified in SourceCodester Hotel Reservation System 1.0.
  The impacted element is an unknown function of the file deleteuser.php. Such
  manipulation of the argument ID leads to sql injection. It is possible to
  launch …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: fabian
product: hotel_reservation_system
affected:
  - hotel_reservation_system = 1.0
published: '2025-09-17'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10623'
references:
  - url: 'https://github.com/aCas1o/cve_report02/blob/main/report.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.324651'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.324651'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.650221'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
  - url: 'https://github.com/aCas1o/cve_report02/blob/main/report.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00478
epssPercentile: 0.38792
ingestedAt: '2026-09-26T00:22:39.945Z'
---

## Overview

A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

## Affected

- `hotel_reservation_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
