CVE-2023-49271 MEDIUM

CVE-2023-49271: Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS)

Vendor Kashipara Group
Product Hotel Management
Weakness CWE-79 · XSS
Published December 20, 2023
Last update May 19, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.

Key dates

02Disclosure timeline

December 20, 2023 CVE published
May 19, 2025 Record updated