Vendorsjayeshhotel_management_systemall versions
Vulnerabilities

jayesh kavthiya Hotel Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2024-42773
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.
Published 2024-08-22 · Analyzed
9.1EPSS 0.005
CVE-2024-42775
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.
Published 2024-08-22 · Analyzed
9.1EPSS 0.005
CVE-2024-42772
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.
Published 2024-08-22 · Analyzed
7.5EPSS 0.005
CVE-2024-42774
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.
Published 2024-08-22 · Analyzed
7.5EPSS 0.004
CVE-2024-42767
Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
Published 2024-08-22 · Analyzed
7.2EPSS 0.006
CVE-2024-42776
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
Published 2024-08-22 · Analyzed
7.2EPSS 0.005
CVE-2024-42768
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.
Published 2024-08-22 · Analyzed
6.8EPSS 0.002
CVE-2024-42769
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.
Published 2024-08-22 · Analyzed
6.1EPSS 0.005
CVE-2023-49270
Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS)
Published 2023-12-20 · Analyzed
5.4EPSS 0.004
CVE-2023-49271
Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS)
Published 2023-12-20 · Analyzed
5.4EPSS 0.004
CVE-2023-49272
Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS)
Published 2023-12-20 · Analyzed
5.4EPSS 0.004
CVE-2023-49269
Hotel Management v1.0 - Multiple Reflected Cross-Site Scripting (XSS)
Published 2023-12-20 · Analyzed
5.4EPSS 0.004
CVE-2024-42771
A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.
Published 2024-08-22 · Analyzed
4.8EPSS 0.005
CVE-2024-42770
A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter.
Published 2024-08-22 · Analyzed
4.7EPSS 0.005