Executive brief
A security vulnerability exists in the itsourcecode Online Hotel Management System, a software package used for managing hotel operations. An attacker can inject malicious scripts into the system's database through the amenities management interface. If a staff member or administrator views the affected page, the script could execute in their browser, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive login information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in itsourcecode Online Hotel Management System 1.0 within the '/admin/mod_amenities/controller.php' component. The application fails to properly sanitize or escape the 'Name' parameter during a POST request when adding new amenities. This allows a remote attacker to submit a malicious payload (e.g., JavaScript within an HTML tag) that is permanently stored in the 'amenities' database table. When an administrative user subsequently views the amenities list, the malicious script executes in their browser context. This can lead to session cookie theft or unauthorized administrative actions. No authentication is reportedly required to reach the vulnerable endpoint.
Affected products
- itsourcecode Online Hotel Management System 1.0
Timeline
- 2026-05-30: disclosed: Initial disclosure on GitHub by researcher Hh-176
- 2026-06-29: advisory: NVD publication date