Hotel Management System是印度Prem Chand Saini个人开发者的一个基于酒店管理系统的 MIS 项目。 Hotel Management System v1.0存在跨站脚本漏洞,该漏洞源于servation.php 中的 adults参数以纯文本形式复制到 HTML 文档中的 tags之间,任何输入都会在应用程序的响应中未经修改地回显。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kashipara Group | Hotel Management | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-5007 | 8.8 HIGH | Student Information System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-5010 | 8.8 HIGH | Student Information System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-5011 | 8.8 HIGH | Student Information System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-49270 | 5.4 MEDIUM | Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS) |
| CVE-2023-49271 | 5.4 MEDIUM | Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS) |
| CVE-2023-49272 | 5.4 MEDIUM | Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS) |
No comments yet