GHSA-hf48-72gv-xr79LowCVSS 4.3
A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0....
🔗 CVE IDs covered (1)
📋 Description
A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-10289
- https://code-projects.org
- https://github.com/Xmyronn/Hotel-and-Tourism-Reservation-System---Stored-XSS.git
- https://vuldb.com/cve/CVE-2026-10289
- https://vuldb.com/submit/825934
- https://vuldb.com/vuln/367582
- https://vuldb.com/vuln/367582/cti
- https://github.com/advisories/GHSA-hf48-72gv-xr79