A vulnerability classified as critical was found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Executing manipulation of the argument usname can lead to sql injection.
This vulnerability is handled as CVE-2025-13076. The attack can be executed remotely. Additionally, an exploit exists.