A vulnerability labeled as critical has been found in SourceCodester Wedding Reservation Management System 1.0. Impacted is the function
insertReservation
of the file function.php. Such manipulation of the argument number leads to sql injection.
This vulnerability is documented as CVE-2025-11479. The attack can be executed remotely. Additionally, an exploit exists.