CVE-2019-25489 | Doditsolutions Homey BNB V4 ajax_refresh_subtotal hosting_id sql injection (Exploit 46616 / EDB-46616)
A vulnerability, which was classified as critical, was found in Doditsolutions Homey BNB V4. Impacted is an unknown function of the file rooms/ajax_refresh_subtotal. The manipulation of the argument hosting_id results in sql injection.
This vulnerability is known as CVE-2019-25489. It is possible to launch the attack remotely. Furthermore, an exploit is available.