CVE-2026-13556: fallo de gravedad media en itsourcecode Online Hotel Management System
itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
Publicada el · Actualizada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.5%
probabilidad de explotación
0.5%top 61% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
itsourcecode · Online Hotel Management SystemPoCs públicas encontradas — 1
cve_referencegithub.com/Hh-176/CVE/issues/7no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — itsourcecode Online Hotel Management System
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-13553MEDIUMitsourcecode Online Hotel Management System controller.php add unrestricted uploadEPSS 0.5%CVE-2026-13557MEDIUMitsourcecode Online Hotel Management System POST Request controller.php add cross site scriptingEPSS 0.5%CVE-2026-13554MEDIUMitsourcecode Online Hotel Management System POST Request controller.php add cross site scriptingEPSS 0.5%CVE-2026-14688MEDIUMitsourcecode Online Hotel Management System login.php sql injectionEPSS 0.4%CVE-2026-13555MEDIUMitsourcecode Online Hotel Management System controller.php add sql injectionEPSS 0.4%CVE-2026-13552MEDIUMitsourcecode Online Hotel Management System controller.php edit sql injectionEPSS 0.4%