Executive brief
A vulnerability exists in the Online Hotel Management System, a web application used for managing hotel operations. An attacker can inject malicious scripts into the system's database through the user management interface. If a legitimate user views the affected data, the script could execute in their browser, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive information like login cookies.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in itsourcecode Online Hotel Management System 1.0 within the /admin/mod_users/controller.php file. The application fails to properly sanitize or escape the 'Name' parameter during a POST request handled by the 'edit' action. This allows a remote, unauthenticated attacker to submit a malicious payload (e.g., an img tag with an onerror attribute) that is permanently stored in the 'users' database table. When an administrator or another user views the user list or edit page, the payload executes in their browser context. This can be used to steal session cookies or perform unauthorized actions. No authentication is required to reach the vulnerable endpoint.
Affected products
- itsourcecode Online Hotel Management System 1.0
Timeline
- 2026-05-30: disclosed: Initial disclosure on GitHub by researcher Hh-176
- 2026-06-29: advisory: NVD publication date