Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-2692: Wedding-Hall-Booking-System/WHBS-XSS.md at main · Jamison2022/Wedding-Hall-Booking-System

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205815.

CVE
#xss#vulnerability#php

WHBS-XSS

The Wedding Hall Booking System published in SourceCodester has multiple Cross-site scripting vulnerabilities. The system does not do anything with input and output. Attackers can construct malicious code to steal user and administrator cookies.

Contact Us

Booking Form

Fires when the user views the booking

Fires when the admin views the booking

/whbs/admin/?page=bookings

Profile page

Modify the profile

/whbs/?page=manage_account

Fires when the user views the profile

Fires when the admin views the Client Lists

/whbs/admin/?page=clients

Staff user profile

Fired when an administrator visits the User List page.

/whbs/admin/?page=user/list

All of the above vulnerabilities can return cookies.

Link

https://www.sourcecodester.com/php/15154/wedding-hall-booking-system-phpoop-free-source-code.html

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907