Junglewise Threat Intelligence

CVE-2025-60308: code-projects Simple Online Hotel Reservation System XSS in Add Room function

CVE-2025-60308 · Severity: medium · CVSS 4.1 · Published 2025-10-10

Vendors: Fabian, Code-Projects.

Executive brief

The Simple Online Hotel Reservation System contains a security flaw that allows an attacker to inject malicious scripts into the room description field. If an administrator views the affected room information, the script can automatically run in their browser, potentially allowing the attacker to steal login cookies or session information. This could lead to unauthorized access to the management interface of the reservation system.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in code-projects Simple Online Hotel Reservation System 1.0 within the 'Add Room' functionality. The application fails to properly neutralize user-supplied input in the 'Description' field before rendering it on the page. An attacker with low-level privileges can inject malicious JavaScript which executes in the context of any user, including administrators, who views the room information. This can be used to perform session hijacking by exfiltrating session cookies. No patch is currently mentioned in the advisory.

Affected products

  • code-projects Simple Online Hotel Reservation System 1.0

Timeline

  • 2025-10-10: disclosed
  • 2025-10-10: advisory

References