CVE-2019-25530: Hotel-Booking-Script Uhotelbooking System
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection techniques to extract sensitive database information.
Affected products
- Hotel-Booking-Script Uhotelbooking System: any version
Published 2026-03-12. Last modified 2026-06-17.