Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
References
Link Resource
https://fluidattacks.com/advisories/lang/ Third Party Advisory
https://www.kashipara.com/ Product
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2023-12-20T19:25:08.511Z

Updated: 2023-12-20T19:25:08.511Z

Reserved: 2023-11-24T16:25:53.193Z


Link: CVE-2023-49272

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-20T20:15:20.010

Modified: 2024-02-01T18:06:05.510


Link: CVE-2023-49272

JSON object: View

cve-icon Redhat Information

No data.

CWE