CVE-2025-15127

HIGH

FantasticLBP Hotels_Server - SQL Injection

Title source: llm
STIX 2.1

Description

A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is some unknown functionality of the file /controller/api/Room.php. Such manipulation of the argument hotelId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.338505
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.338505
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.711809
Issue Tracking exploit issue-tracking
https://github.com/liangmingpku/CVE/issues/1

Scores

CVSS v3 7.3
EPSS 0.0041
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
fantasticlbp/hotels_server < 2019-03-23
Published Dec 28, 2025
Tracked Since Feb 18, 2026