PT-2024-15621 · Unknown · Code-Projects Simple Online Hotel Reservation System

Adarsh C

+1

·

Published

2024-01-13

·

Updated

2024-05-17

·

CVE-2024-0504

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Simple Online Hotel Reservation System version 1.0
Description A vulnerability has been found in the code-projects Simple Online Hotel Reservation System, affecting the file add reserve.php of the Make a Reservation Page component. The issue arises from the manipulation of the Firstname and Lastname arguments with malicious input, such as <script>alert(1)</script>, leading to cross-site scripting. This attack can be initiated remotely.
Recommendations For code-projects Simple Online Hotel Reservation System version 1.0, consider disabling the add reserve.php file or restricting access to it until a patch is available. Additionally, avoid using the Firstname and Lastname arguments in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-0504

Affected Products

Code-Projects Simple Online Hotel Reservation System