Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2023-34487

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points exist in the login password input box. This vulnerability can be exploited through time-based blind injection.
Attacker Value
Unknown

CVE-2023-34486

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote code execution can be achieved by entering malicious code in the date selection box.
Attacker Value
Unknown

CVE-2023-2565

Disclosure Date: May 07, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problematic. This vulnerability affects unknown code of the file ajax.php of the component POST Parameter Handler. The manipulation of the argument complaint_type with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228172.
Attacker Value
Unknown

CVE-2022-36254

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
Attacker Value
Unknown

CVE-2022-28110

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.
Attacker Value
Unknown

CVE-2022-27475

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.
Attacker Value
Unknown

CVE-2019-18387

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.