Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2022-2291
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2022-28110
Disclosure Date: May 10, 2022 (last updated February 23, 2025)
Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.
0
Attacker Value
Unknown
CVE-2022-27475
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.
0
Attacker Value
Unknown
CVE-2021-41651
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.
0
Attacker Value
Unknown
CVE-2020-21012
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
0
Attacker Value
Unknown
CVE-2019-18387
Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
0