Executive brief
A security vulnerability exists in the itsourcecode Online Hotel Management System, a software package used for managing hotel bookings and operations. An attacker can inject malicious scripts into the system's database by submitting a specially crafted room name. If a staff member or administrator views the affected room entry, the script could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in itsourcecode Online Hotel Management System 1.0 within the /admin/mod_room/controller.php script. The application fails to properly sanitize or escape the 'name' POST parameter when the 'action' is set to 'add'. This allows a remote attacker to submit a malicious payload (e.g., an image tag with an onerror attribute) that is permanently stored in the 'room' database table. When an administrative user subsequently views the room list or details, the payload is rendered without encoding, leading to arbitrary JavaScript execution in the victim's browser session. This can be used for session hijacking or credential theft. No authentication is reportedly required to reach the vulnerable endpoint in the default configuration.
Affected products
- itsourcecode Online Hotel Management System 1.0
Timeline
- 2026-05-30: disclosed: Vulnerability details and PoC shared on GitHub
- 2026-06-29: advisory: CVE published and NVD record created