Executive brief
A security vulnerability exists in the SourceCodester Ship Ferry Ticket Reservation System, a web application used for managing ferry bookings. An attacker with administrative access can inject malicious scripts into the system via the username field. If another user views the compromised user management page, the script could execute in their browser, potentially leading to unauthorized actions or information disclosure within the application session.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Ship Ferry Ticket Reservation System 1.0 within the /admin/?page=user/manage_user endpoint. The vulnerability is caused by improper neutralization of input in the 'Username' argument. An attacker with high privileges (PR:H) can submit a crafted username containing JavaScript. When an administrator or another user views the user management interface, the malicious payload executes in the context of their browser session. This can lead to session hijacking or unauthorized modification of application data. A public exploit has been disclosed.
Affected products
- SourceCodester Ship Ferry Ticket Reservation System 1.0
Timeline
- 2026-06-05: disclosed: Public disclosure of the exploit and vulnerability details.
- 2026-06-05: advisory: CVE-2026-11338 published.
References
- https://medium.com/@hemantrajbhati5555/stored-cross-site-scripting-stored-xss-in-username-field-leads-to-arbitrary-javascript-execution-cd377841da30
- https://vuldb.com/cve/CVE-2026-11338
- https://vuldb.com/submit/832571
- https://vuldb.com/vuln/368880
- https://vuldb.com/vuln/368880/cti
- https://www.sourcecodester.com/