PT-2024-30139 · Unknown · Kashipara Hotel Management System

Published

2024-08-22

·

Updated

2024-08-23

·

CVE-2024-42769

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kashipara Hotel Management System version 1.0
Description A Reflected Cross Site Scripting (XSS) issue was found in the "/core/signup user.php" endpoint of the system, allowing remote attackers to execute arbitrary code via the user fname and user lname parameters. This could enable malicious scripts to hijack user sessions.
Recommendations For Kashipara Hotel Management System version 1.0, patch and validate user input as soon as possible to prevent attacks. As a temporary workaround, consider restricting access to the "/core/signup user.php" endpoint or validating and sanitizing the user fname and user lname parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-42769

Affected Products

Kashipara Hotel Management System