Cross-site Scripting Vulnerability in VikBooking Hotel Booking Engine by e4jvikwp
CVE-2026-42683

7.1HIGH

What is CVE-2026-42683?

The VikBooking Hotel Booking Engine & PMS by e4jvikwp contains a cross-site scripting (XSS) vulnerability, specifically an improper neutralization of input during web page generation. This flaw enables attackers to execute arbitrary scripts in the context of users' web browsers, potentially leading to data theft or unwanted actions on affected websites. The issue affects all versions from n/a to 1.8.8, highlighting the importance of applying security updates to mitigate risks associated with this vulnerability.

Affected Version(s)

VikBooking Hotel Booking Engine & PMS <= 1.8.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Evan NR | Patchstack Bug Bounty Program
.