Jayesh
Jayesh Hotel Management System: vulnerabilidades y CVE
Jayesh Hotel Management System tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-42773 | Crítica (9.1) | 0.48% | — | 22 ago 2024 | An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the… |
| CVE-2024-42767 | Alta (7.2) | 0.58% | — | 22 ago 2024 | Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php. |
| CVE-2024-42776 | Alta (7.2) | 0.53% | — | 22 ago 2024 | Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php. |
| CVE-2024-42775 | Crítica (9.1) | 0.48% | — | 22 ago 2024 | An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the… |
| CVE-2024-42774 | Alta (7.5) | 0.41% | — | 22 ago 2024 | An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator… |
| CVE-2024-42772 | Alta (7.5) | 0.48% | — | 22 ago 2024 | An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section. |
| CVE-2024-42768 | Media (6.8) | 0.18% | — | 22 ago 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php. |
| CVE-2024-42771 | Media (4.8) | 0.45% | — | 22 ago 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name"… |
| CVE-2024-42770 | Media (4.7) | 0.51% | — | 22 ago 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter. |
| CVE-2024-42769 | Media (6.1) | 0.47% | — | 22 ago 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and… |
| CVE-2023-49272 | Media (5.4) | 0.37% | — | 20 dic 2023 | Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text… |
| CVE-2023-49271 | Media (5.4) | 0.38% | — | 20 dic 2023 | Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text… |
| CVE-2023-49270 | Media (5.4) | 0.38% | — | 20 dic 2023 | Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text… |
| CVE-2023-49269 | Media (5.4) | 0.37% | — | 20 dic 2023 | Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between… |