PT-2025-52345 · Yohanawi · Hotel Management System
Solonbarroso
·
Published
2025-12-18
·
Updated
2025-12-20
·
CVE-2025-63949
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
yohanawi Hotel Management System version 87e004a
Description
A Reflected Cross-Site Scripting (XSS) issue exists in yohanawi Hotel Management System. This allows a remote attacker to execute arbitrary web script through the
error parameter in the 'pages/room.php' file. The vulnerable parameter is error. The affected API endpoint is '/pages/room.php'.Recommendations
Apply the fix for version 87e004a. As a temporary workaround, sanitize the
error parameter in the '/pages/room.php' file to prevent the execution of arbitrary web scripts.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotel Management System