uHotelBooking System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in uHotelBooking System, allowing unauthenticated attackers to manipulate database queries. The vulnerability arises from improper handling of the 'system_page' GET parameter in 'index.php', where attackers can inject SQL code. This flaw can be exploited using time-based blind SQL injection techniques to extract sensitive information from the database.

Impact

Exploitation of this vulnerability allows for unauthorized database access and manipulation, potentially leading to the disclosure of sensitive information.

Reproduction

To reproduce this vulnerability, send a crafted request to 'index.php' with a malicious 'system_page' value that includes SQL injection payloads. The injected SQL code can be designed to exploit the application's database query handling, such as by using time-based blind SQL injection techniques to extract data.

Added: Mar 12, 2026, 4:24 PM
Updated: Mar 12, 2026, 4:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.