Executive brief
A security vulnerability exists in the Online Hotel Booking System, a web application used for managing hotel reservations. An attacker can exploit this flaw to execute malicious scripts in the browser of a legitimate user, such as a hotel customer or staff member. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability was identified in the Booking Endpoint of code-projects Online Hotel Booking 1.0. The issue resides in the /booknow.php file due to improper neutralization of user-supplied input in the 'roomname' parameter. A remote attacker can exploit this by tricking a user into clicking a specially crafted link containing malicious JavaScript. If successful, the script executes within the context of the victim's browser session, potentially allowing for session hijacking or unauthorized manipulation of the web page. A proof-of-concept exploit is publicly available.
Affected products
- code-projects Online Hotel Booking System 1.0
Timeline
- 2026-04-07: disclosed: Initial disclosure of the vulnerability
- 2026-04-07: advisory: VulDB and NVD advisory published