Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-06168
HistoryJan 24, 2024 - 12:00 a.m.

Simple Online Hotel Reservation System Cross-Site Scripting Vulnerability

2024-01-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
online hotel reservation
web script
html
cross-site scripting
vulnerability
user-supplied data
exploited
attacker

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.7%

Simple Online Hotel Reservation System is an online hotel reservation system. A cross-site scripting vulnerability exists in Simple Online Hotel Reservation System version 1.0, which stems from the lack of effective filtering and escaping of user-supplied data in the add_reserve.php file, and can be exploited by an attacker to execute arbitrary Web script or HTML by injecting a crafted payload.

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.7%

Related for CNVD-2024-06168