Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
| Software | From | Fixed in |
|---|---|---|
| gvnpatidar / hotel_management_system | 1.0 | 1.0.x |