PT-2026-43660 · Unknown · Booking Manager
Published
2026-05-27
·
Updated
2026-05-27
·
CVE-2026-42751
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Booking Manager versions prior to 2.1.19
Description
Booking Manager contains a stored cross-site scripting (XSS) flaw, which occurs when the application fails to properly neutralize input during the generation of web pages. This allows an attacker to store malicious scripts on the server that are later executed in the browsers of other users.
Recommendations
Update to a version later than 2.1.18.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Booking Manager