PT-2024-27759 · Unknown · Code-Projects Restaurant Reservation System

Sandeep Rajauriya

·

Published

2024-06-18

·

Updated

2026-03-12

·

CVE-2024-37800

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CodeProjects Restaurant Reservation System version 1.0
Description The issue is related to a reflected cross-site scripting (XSS) vulnerability. This vulnerability occurs via the Date parameter at the "index.php" endpoint. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For CodeProjects Restaurant Reservation System version 1.0, consider restricting access to the Date parameter in the "index.php" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the Date parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-37800

Affected Products

Code-Projects Restaurant Reservation System