A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of the argument city leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
📦
avl_rooms
Vendor: anisha
Actively Exploited
0
CISA KEV List
PoC / Exploits
2
Code Available
Total RCEs
0
Remote Access
Total CVEs
6
Total Indexed
Avg. EPSS
0.40%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
5.5
CVSS
CVE-2025-7606
Exploit Found
Severity: MEDIUM
5.5
CVSS
CVE-2025-7605
Exploit Found
A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument first_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: MEDIUM