PT-2025-52345 · Yohanawi · Hotel Management System

Solonbarroso

·

Published

2025-12-18

·

Updated

2025-12-20

·

CVE-2025-63949

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions yohanawi Hotel Management System version 87e004a
Description A Reflected Cross-Site Scripting (XSS) issue exists in yohanawi Hotel Management System. This allows a remote attacker to execute arbitrary web script through the error parameter in the 'pages/room.php' file. The vulnerable parameter is error. The affected API endpoint is '/pages/room.php'.
Recommendations Apply the fix for version 87e004a. As a temporary workaround, sanitize the error parameter in the '/pages/room.php' file to prevent the execution of arbitrary web scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63949

Affected Products

Hotel Management System