Medium severity5.4NVD Advisory· Published Jul 14, 2021· Updated Jun 17, 2026
CVE-2020-25444
CVE-2020-25444
Description
Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details” page, (3) “Pricing code” and “name” fields under the “Manage Tour” page, and (4) all the labels under the “Menu” section.
Affected products
3cpe:2.3:a:bookingcore:booking_core:1.7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bookingcore:booking_core:1.7.0:*:*:*:*:*:*:*
- (no CPE)range: =1.7.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.