CVE-2026-13557 PUBLISHED

itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting

Assigner: VulDB
Reserved: 28.06.2026 Published: 29.06.2026 Updated: 29.06.2026

A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor itsourcecode
Product Online Hotel Management System
Versions
  • Version 1.0 is affected

Credits

  • Hh-176 (VulDB User) reporter

References

Problem Types

  • Cross Site Scripting CWE
  • Code Injection CWE