CVE-2023-49272

CVSS V2 None CVSS V3 None
Description
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
Overview
  • CVE ID
  • CVE-2023-49272
  • Assigner
  • Fluid Attacks
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-12-20T19:25:08.511Z
  • Last Modified Date
  • 2023-12-20T19:25:08.511Z
References
Reference URL Reference Tags
https://fluidattacks.com/advisories/lang/ third-party-advisory
https://www.kashipara.com/ product
History
Created Old Value New Value Data Type Notes
2024-06-25 13:07:50 Added to TrackCVE