CVE-2026-13557: medium-severity vulnerability in itsourcecode Online Hotel Management System
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
Published
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
itsourcecode · Online Hotel Management Systempublic PoCs found — 1
cve_referencegithub.com/Hh-176/CVE/issues/8unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — itsourcecode Online Hotel Management System
In the same product, most dangerous first.
CVE-2026-13553MEDIUMitsourcecode Online Hotel Management System controller.php add unrestricted uploadEPSS 0.5%CVE-2026-13556MEDIUMitsourcecode Online Hotel Management System POST Request controller.php edit cross site scriptingEPSS 0.5%CVE-2026-13554MEDIUMitsourcecode Online Hotel Management System POST Request controller.php add cross site scriptingEPSS 0.5%CVE-2026-14688MEDIUMitsourcecode Online Hotel Management System login.php sql injectionEPSS 0.4%CVE-2026-13555MEDIUMitsourcecode Online Hotel Management System controller.php add sql injectionEPSS 0.4%CVE-2026-13552MEDIUMitsourcecode Online Hotel Management System controller.php edit sql injectionEPSS 0.4%