PT-2022-11982 · Sourcecodester · Sourcecodester Multi Restaurant Table Reservation System
Published
2022-01-20
·
Updated
2022-01-25
·
CVE-2021-44091
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Courcecodester Multi Restaurant Table Reservation System version 1.0
Description
A Cross-Site Scripting (XSS) issue exists in the register.php file via the
fullname, phone, and address parameters. This allows for potential malicious script execution.Recommendations
For Courcecodester Multi Restaurant Table Reservation System version 1.0, consider validating and sanitizing user input for the
fullname, phone, and address parameters in the register.php file to prevent XSS attacks. As a temporary workaround, restrict access to the register.php file until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Multi Restaurant Table Reservation System