Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.
History

Sat, 28 Mar 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Wecodex hotel Cms
CPEs cpe:2.3:a:wecodex:hotel_cms:1.0:*:*:*:*:*:*:*
Vendors & Products Wecodex hotel Cms
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Wecodex
Wecodex wecodex Hotel Cms
Vendors & Products Wecodex
Wecodex wecodex Hotel Cms

Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.
Title Wecodex Hotel CMS 1.0 SQL Injection via Admin Login
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-03-26T11:39:48.998Z

Updated: 2026-03-28T02:14:12.286Z

Reserved: 2026-03-06T12:00:30.883Z

Link: CVE-2018-25195

cve-icon Vulnrichment

Updated: 2026-03-28T02:14:07.340Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-26T12:16:04.467

Modified: 2026-03-27T21:00:18.543

Link: CVE-2018-25195

cve-icon Redhat

No data.