PT-2025-52345 · Yohanawi · Hotel Management System
Solonbarroso
·
Publicado
2025-12-18
·
Atualizado
2025-12-20
·
CVE-2025-63949
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
yohanawi Hotel Management System version 87e004a
Description
A Reflected Cross-Site Scripting (XSS) issue exists in yohanawi Hotel Management System. This allows a remote attacker to execute arbitrary web script through the
error parameter in the 'pages/room.php' file. The vulnerable parameter is error. The affected API endpoint is '/pages/room.php'.Recommendations
Apply the fix for version 87e004a. As a temporary workaround, sanitize the
error parameter in the '/pages/room.php' file to prevent the execution of arbitrary web scripts.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hotel Management System