A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester...
Vulnerability Description
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42662
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.sourcecodester.com/php/14241/online-event-booking-and-reservation-system-phpmysql.html
- http://packetstormsecurity.com/files/164615/Online-Event-Booking-And-Reservation-System-1.0-Cross-Site-Scripting.html
- https://github.com/TheHackingRabbi/CVE-2021-42662
- https://www.exploit-db.com/exploits/50450
More from online event booking and reservation system project
View All →Affected Vendor
online event booking and reservation system project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.