Junglewise Threat Intelligence

CVE-2024-13064: Akinsoft MyRezzta cross-site scripting

CVE-2024-13064 · Severity: medium · CVSS 4.3 · Published 2025-09-03

Technologies: AKINSOFT MyRezzta. Vendors: AKINSOFT.

Executive brief

Akinsoft MyRezzta, a reservation and management software, contains a security vulnerability that allows for cross-site scripting (XSS). An attacker with high-level privileges could inject malicious scripts into the application, which would then execute in the browser of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A stored or reflected Cross-Site Scripting (XSS) vulnerability exists in Akinsoft MyRezzta versions s2.02.02 through v2.05.01. The flaw stems from improper neutralization of user-supplied input during the generation of web pages (CWE-79). An attacker with high privileges (PR:H) can exploit this over the network by injecting malicious scripts that execute when a victim interacts with the affected page. Successful exploitation requires user interaction (UI:R) and can result in a limited impact on confidentiality, integrity, and availability. Users are advised to upgrade to version 2.05.01 or later to remediate the issue.

Affected products

  • Akinsoft MyRezzta s2.02.02 to v2.05.01 (exclusive)

Timeline

  • 2025-09-03: disclosed
  • 2025-09-03: advisory

References

Related threats