vendor:
Hotels Booking System
by:
HackXBack
8,8
CVSS
HIGH
Cross Site Request Forgery, Cross Site Scripting, Local File disclure
352, 79, 200
CWE
Product Name: Hotels Booking System
Affected Version From: V3.0
Affected Version To: V3.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Hotel Booking System V3.0 – Multiple Vulnerabilties
The first vulnerability is a Cross Site Request Forgery (CSRF) vulnerability which allows an attacker to add an admin user to the system. The second vulnerability is a Cross Site Scripting (XSS) vulnerability which allows an attacker to inject malicious JavaScript code into the system. The third vulnerability is a Local File disclure vulnerability which allows an attacker to download sensitive files from the system.
Mitigation:
The application should implement a CSRF token to prevent CSRF attacks. The application should also validate user input to prevent XSS attacks. The application should also restrict access to sensitive files.