CVE-2026-13554: falha de média gravidade em itsourcecode Online Hotel Management System
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
Publicada em · Atualizada em
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 5.3epss 0.5%
probabilidade de exploração
0.5%top 61% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Produtos afetados
itsourcecode · Online Hotel Management SystemPoCs públicas encontradas — 1
cve_referencegithub.com/Hh-176/CVE/issues/5não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — itsourcecode Online Hotel Management System
No mesmo produto, das mais perigosas para as menos.
CVE-2026-13553MEDIUMitsourcecode Online Hotel Management System controller.php add unrestricted uploadEPSS 0.5%CVE-2026-13557MEDIUMitsourcecode Online Hotel Management System POST Request controller.php add cross site scriptingEPSS 0.5%CVE-2026-13556MEDIUMitsourcecode Online Hotel Management System POST Request controller.php edit cross site scriptingEPSS 0.5%CVE-2026-14688MEDIUMitsourcecode Online Hotel Management System login.php sql injectionEPSS 0.4%CVE-2026-13555MEDIUMitsourcecode Online Hotel Management System controller.php add sql injectionEPSS 0.4%CVE-2026-13552MEDIUMitsourcecode Online Hotel Management System controller.php edit sql injectionEPSS 0.4%