PT-2026-45554 · Code Projects · Hotel/Tourism Reservation System

·

CVE-2026-10289

·

Published

2026-06-01

·

Updated

2026-07-22

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions code-projects Hotel and Tourism Reservation System version 1.0
Description A remote cross-site scripting issue exists in an unknown function within the /ht/tour.php file. This occurs when the name, email, people, and number arguments are manipulated. Cross-site scripting is a technique where malicious scripts are injected into trusted websites.
Recommendations As a temporary workaround, restrict access to the /ht/tour.php file or avoid using the name, email, people, and number parameters until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10289

Affected Products

Hotel/Tourism Reservation System