PT-2026-43660 · Unknown · Booking Manager

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-42751

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Booking Manager versions prior to 2.1.19
Description Booking Manager contains a stored cross-site scripting (XSS) flaw, which occurs when the application fails to properly neutralize input during the generation of web pages. This allows an attacker to store malicious scripts on the server that are later executed in the browsers of other users.
Recommendations Update to a version later than 2.1.18.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-42751

Affected Products

Booking Manager