vendor:
Online Hotel Reservation System
by:
Mesut Cetin
7.5
CVSS
HIGH
Cross-site request forgery (CSRF)
352
CWE
Product Name: Online Hotel Reservation System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Kali Linux 2020.4, PHP 7.4.13, mysqlnd 7.4.13, Apache/2.4.46 (Unix), OpenSSL/1.1.1h, mod_perl/2.0.11 Perl/v5.32.0
2021
Online Hotel Reservation System 1.0 – Cross-site request forgery (CSRF)
Vulnerable to Cross-site request forgery (CSRF), can lead to full account takeover of Administrator account.
Mitigation:
Implement CSRF tokens and validate them on the server-side to prevent CSRF attacks.