PT-2025-31506 · Unknown · Campcodes Online Hotel Reservation System
Xiaojiesecqwq
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-8380
Xiaojiesecqwq
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-8380
4.0
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Campcodes Online Hotel Reservation System version 1.0
Description:
A cross site scripting issue exists in Campcodes Online Hotel Reservation System 1.0. The vulnerability affects unknown code within the `/admin/add query account.php` file. Manipulation of the `Name` argument can lead to exploitation. The exploit has been publicly disclosed.
Recommendations:
As a temporary workaround, consider restricting access to the `/admin/add query account.php` file until a fix is available.
Sanitize the `Name` argument to prevent the injection of malicious scripts.
Exploit
Fix
XSS
Code Injection