Vulnerability Description
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jayesh | Hotel Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/lang/Third Party Advisory
- https://www.kashipara.com/Product
- https://fluidattacks.com/advisories/lang/Third Party Advisory
- https://www.kashipara.com/Product
FAQ
What is CVE-2023-49272?
CVE-2023-49272 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document ...
How severe is CVE-2023-49272?
CVE-2023-49272 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49272?
Check the references section above for vendor advisories and patch information. Affected products include: Jayesh Hotel Management System.