CVE-2023-49989

CRITICAL

Hotel Booking Management v1.0 - SQL Injection via update.php id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-49989. PoCs published by geraldoalcantara.

AI-analyzed exploit summary This repository provides a functional SQL injection exploit for CVE-2023-49989 in Hotel Booking Management v1.0, targeting the 'id' parameter in update.php. The PoC includes a time-based blind SQLi payload and a sample HTTP request demonstrating the vulnerability.

Description

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

Exploits (1)

nomisec WORKING POC 1 stars
by geraldoalcantara · poc
https://github.com/geraldoalcantara/CVE-2023-49989

This repository provides a functional SQL injection exploit for CVE-2023-49989 in Hotel Booking Management v1.0, targeting the 'id' parameter in update.php. The PoC includes a time-based blind SQLi payload and a sample HTTP request demonstrating the vulnerability.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Hotel Booking Management v1.0
No auth needed
Prerequisites: Access to the vulnerable update.php endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0078
EPSS Percentile 51.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
pratham-jaiswal/hotel_booking_management_system 1.0
Published Mar 07, 2024
Tracked Since Feb 18, 2026