PT-2024-30139 · Unknown · Kashipara Hotel Management System
Published
2024-08-22
·
Updated
2024-08-23
·
CVE-2024-42769
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kashipara Hotel Management System version 1.0
Description
A Reflected Cross Site Scripting (XSS) issue was found in the "/core/signup user.php" endpoint of the system, allowing remote attackers to execute arbitrary code via the
user fname and user lname parameters. This could enable malicious scripts to hijack user sessions.Recommendations
For Kashipara Hotel Management System version 1.0, patch and validate user input as soon as possible to prevent attacks. As a temporary workaround, consider restricting access to the "/core/signup user.php" endpoint or validating and sanitizing the
user fname and user lname parameters to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kashipara Hotel Management System