Executive brief
A Hotel and Tourism Reservation system in PHP contains a reflected cross-site scripting (XSS) vulnerability in the room parameter of the /ht/details.php endpoint. An attacker can inject malicious JavaScript code that executes in a victim's browser when they visit a crafted link, potentially allowing session hijacking, credential theft, or malware distribution to hotel guests and staff.
Technical details
A reflected XSS vulnerability exists in the room parameter of /ht/details.php due to insufficient input validation and output encoding. The attack vector is network-based and requires no authentication; an attacker can craft a URL with a malicious payload in the room parameter and trick a user into clicking the link. Upon rendering the page, the unsanitized parameter is reflected into the HTML/JavaScript context, executing the attacker's script in the victim's session context. The vulnerability affects Hotel and Tourism Reservation in PHP version 1.0, and exploitation has been publicly disclosed.
Affected products
- code-projects Hotel and Tourism Reservation 1.0
Timeline
- 2026-09-06: disclosed