Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS)
CVE-2023-49270
5.4MEDIUM
What is CVE-2023-49270?
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
Affected Version(s)
Hotel Management 1.0