PT-2025-52345 · Yohanawi · Hotel Management System

Solonbarroso

·

Publicado

2025-12-18

·

Atualizado

2025-12-20

·

CVE-2025-63949

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions yohanawi Hotel Management System version 87e004a
Description A Reflected Cross-Site Scripting (XSS) issue exists in yohanawi Hotel Management System. This allows a remote attacker to execute arbitrary web script through the error parameter in the 'pages/room.php' file. The vulnerable parameter is error. The affected API endpoint is '/pages/room.php'.
Recommendations Apply the fix for version 87e004a. As a temporary workaround, sanitize the error parameter in the '/pages/room.php' file to prevent the execution of arbitrary web scripts.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-63949

Produtos afetados

Hotel Management System