PT-2022-11982 · Sourcecodester · Sourcecodester Multi Restaurant Table Reservation System

Published

2022-01-20

·

Updated

2022-01-25

·

CVE-2021-44091

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Courcecodester Multi Restaurant Table Reservation System version 1.0
Description A Cross-Site Scripting (XSS) issue exists in the register.php file via the fullname, phone, and address parameters. This allows for potential malicious script execution.
Recommendations For Courcecodester Multi Restaurant Table Reservation System version 1.0, consider validating and sanitizing user input for the fullname, phone, and address parameters in the register.php file to prevent XSS attacks. As a temporary workaround, restrict access to the register.php file until a proper fix is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44091

Affected Products

Sourcecodester Multi Restaurant Table Reservation System