Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2022-48091

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.
Attacker Value
Unknown

CVE-2022-48090

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
Attacker Value
Unknown

CVE-2022-36254

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
Attacker Value
Unknown

CVE-2022-2673

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
A vulnerability was found in Rigatur Online Booking and Hotel Management System aff6409. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Request Handler. The manipulation of the argument email/pass leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205657 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-2292

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown function of the file /ci_hms/massage_room/edit/1 of the component Room Edit Page. The manipulation of the argument massageroomDetails with the input "><script>alert("XSS")</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-2291

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-28110

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.
Attacker Value
Unknown

CVE-2022-27863

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
Attacker Value
Unknown

CVE-2022-27862

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
Attacker Value
Unknown

CVE-2022-27475

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.