Junglewise Threat Intelligence

CVE-2026-86216: code-projects Hotel and Tourism Reservation reflected XSS in room parameter

CVE-2026-86216 · Severity: medium · CVSS 4.3 · Published 2026-09-06

Vendors: Code-Projects.

Executive brief

A Hotel and Tourism Reservation system in PHP contains a reflected cross-site scripting (XSS) vulnerability in the room parameter of the /ht/details.php endpoint. An attacker can inject malicious JavaScript code that executes in a victim's browser when they visit a crafted link, potentially allowing session hijacking, credential theft, or malware distribution to hotel guests and staff.

Technical details

A reflected XSS vulnerability exists in the room parameter of /ht/details.php due to insufficient input validation and output encoding. The attack vector is network-based and requires no authentication; an attacker can craft a URL with a malicious payload in the room parameter and trick a user into clicking the link. Upon rendering the page, the unsanitized parameter is reflected into the HTML/JavaScript context, executing the attacker's script in the victim's session context. The vulnerability affects Hotel and Tourism Reservation in PHP version 1.0, and exploitation has been publicly disclosed.

Affected products

  • code-projects Hotel and Tourism Reservation 1.0

Timeline

  • 2026-09-06: disclosed

References

Related threats