A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation of the argument uid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 24 Nov 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Amttgroup hibos
CPEs cpe:2.3:a:amttgroup:hibos:1.0:*:*:*:*:*:*:*
Vendors & Products Amttgroup hibos

Fri, 14 Nov 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Amttgroup
Amttgroup hotel Broadband Operation System
Vendors & Products Amttgroup
Amttgroup hotel Broadband Operation System

Thu, 13 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation of the argument uid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title AMTT Hotel Broadband Operation System get_firstdate.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-13T19:02:06.768Z

Updated: 2025-11-13T19:36:38.742Z

Reserved: 2025-11-13T12:17:25.051Z

Link: CVE-2025-13123

cve-icon Vulnrichment

Updated: 2025-11-13T19:36:31.371Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-13T19:15:46.820

Modified: 2025-11-24T12:19:51.987

Link: CVE-2025-13123

cve-icon Redhat

No data.