CVE-2023-49269
Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS)
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
Kashipara Group · Hotel ManagementWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →