CVE-2019-18415
https://notcve.org/view.php?id=CVE-2019-18415
Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen. Sourcecodester Restaurant Management System versión 1.0, permite un ataque de tipo XSS por medio de la pantalla "send a message". • https://www.sevenlayers.com/index.php/264-restaurant-management-system-1-0-xss-session-hijack • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-18416
https://notcve.org/view.php?id=CVE-2019-18416
Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member. Sourcecodester Restaurant Management System versión 1.0, permite un ataque de tipo XSS por medio del campo Last Name de un miembro. • https://www.sevenlayers.com/index.php/264-restaurant-management-system-1-0-xss-session-hijack • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •