A vulnerability identified as critical has been detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument email causes sql injection.

This vulnerability is handled as CVE-2025-12856. The attack can be initiated remotely. Additionally, an exploit exists.