Vulnerability Description
A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the component Appointment Booking. The manipulation of the argument fname/lname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://code-projects.org/
- https://github.com/Xmyronn/home-service-system-unauth-stored-xss-admin-takeover-
- https://vuldb.com/submit/800121
- https://vuldb.com/vuln/359664
- https://vuldb.com/vuln/359664/cti
FAQ
What is CVE-2026-7089?
CVE-2026-7089 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the component Appointment Booking. The mani...
How severe is CVE-2026-7089?
CVE-2026-7089 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7089?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.