SourceCodester Hotel and Lodge Management System Unrestricted File Upload Vulnerability

Vulnerability

A critical unrestricted file upload vulnerability has been identified in SourceCodester Hotel and Lodge Management System versions through 1.0. The issue resides in the file /manage_website.php, where the argument website_image/back_login_image can be manipulated to upload files of potentially dangerous types. This vulnerability could be exploited remotely and may lead to arbitrary file upload, with the possibility of executing uploaded files on the server.

Impact

Exploitation of this vulnerability allows for unrestricted file uploads, which could be used to upload malicious files that are executed on the server, potentially leading to remote code execution.

Reproduction

To reproduce this vulnerability, upload a file through the 'website_image/back_login_image' argument on the '/manage_website.php' page. The application does not properly sanitize or filter the uploaded files, allowing for arbitrary file uploads. Intercept the upload request to confirm the vulnerability.

Added: Oct 8, 2025, 10:18 AM
Updated: Oct 8, 2025, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
6.2
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.