CVE-2021-42662
Online Event Booking And Reservation System 1.0 Cross Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
Se presenta una vulnerabilidad de tipo Cross Site Scripting (XSS) almacenada en Sourcecodester Online Event Booking and Reservation System in PHP/MySQL por medio del parámetro Holiday reason. Un atacante puede aprovechar esta vulnerabilidad para ejecutar comandos javascript en nombre de los navegantes del servidor web, que puede conllevar al robo de cookies y más
Online Event Booking and Reservation System version 1.0 suffers from a persistent cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-18 CVE Reserved
- 2021-10-25 CVE Published
- 2022-03-24 First Exploit
- 2024-02-25 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://www.sourcecodester.com/php/14241/online-event-booking-and-reservation-system-phpmysql.html | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Online Event Booking And Reservation System Project Search vendor "Online Event Booking And Reservation System Project" | Online Event Booking And Reservation System Search vendor "Online Event Booking And Reservation System Project" for product "Online Event Booking And Reservation System" | 2.3.0 Search vendor "Online Event Booking And Reservation System Project" for product "Online Event Booking And Reservation System" and version "2.3.0" | - |
Affected
|