CVE-2026-13554: medium-severity vulnerability in itsourcecode Online Hotel Management System
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
Published · Updated
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
itsourcecode · Online Hotel Management Systempublic PoCs found — 1
cve_referencegithub.com/Hh-176/CVE/issues/5unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — itsourcecode Online Hotel Management System
In the same product, most dangerous first.
CVE-2026-13553MEDIUMitsourcecode Online Hotel Management System controller.php add unrestricted uploadEPSS 0.5%CVE-2026-13557MEDIUMitsourcecode Online Hotel Management System POST Request controller.php add cross site scriptingEPSS 0.5%CVE-2026-13556MEDIUMitsourcecode Online Hotel Management System POST Request controller.php edit cross site scriptingEPSS 0.5%CVE-2026-14688MEDIUMitsourcecode Online Hotel Management System login.php sql injectionEPSS 0.4%CVE-2026-13555MEDIUMitsourcecode Online Hotel Management System controller.php add sql injectionEPSS 0.4%CVE-2026-13552MEDIUMitsourcecode Online Hotel Management System controller.php edit sql injectionEPSS 0.4%