Executive brief
jairiidriss RestaurantWebsite is a web application used for restaurant booking and reservations. The application contains a cross-site scripting vulnerability in the "Make a Reservation" feature that allows attackers to inject malicious scripts through the date selection field. An attacker can exploit this remotely to steal customer data, redirect users to phishing sites, or deface the booking interface.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in the "Make a Reservation" component of jairiidriss RestaurantWebsite, affecting the selected_date parameter. The vulnerability allows remote attackers to inject arbitrary JavaScript without authentication by manipulating the date input field. No patch is currently available due to the vendor's non-responsiveness to early disclosure. The product uses continuous delivery with rolling releases, making it difficult to track affected versions.
Affected products
- jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654
Timeline
- 2025-12-01: disclosed: Publicly disclosed via GitHub and NVD
- 2025-12-01: advisory: CVE-2025-13802 published