Cross Site Scripting Vulnerability in SourceCodester Resort Reservation System
CVE-2024-8951
6.1MEDIUM
What is CVE-2024-8951?
A cross site scripting vulnerability exists in the SourceCodester Resort Reservation System 1.0, specifically within the 'manage_fee.php' file. This vulnerability allows an attacker to manipulate the 'towview' parameter in a way that leads to the execution of malicious scripts in the user's browser. The exploit can be executed remotely without the need for physical access, posing a significant risk to users of the system. Publicly disclosed, this vulnerability requires immediate attention to mitigate potential attacks aimed at exploiting the system.