Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
References
Link | Resource |
---|---|
https://fluidattacks.com/advisories/lang/ | Third Party Advisory |
https://www.kashipara.com/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-12-20 20:15
Updated : 2023-12-26 21:41
NVD link : CVE-2023-49270
Mitre link : CVE-2023-49270
CVE.ORG link : CVE-2023-49270
JSON object : View
Products Affected
kashipara
- hotel_management
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')