Medium severity5.4NVD Advisory· Published Nov 5, 2021· Updated Jun 17, 2026
CVE-2021-42662
CVE-2021-42662
Description
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Sourcecodester/Online Event Booking and Reservation Systemdescription
- cpe:2.3:a:online_event_booking_and_reservation_system_project:online_event_booking_and_reservation_system:2.3.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/164615/Online-Event-Booking-And-Reservation-System-1.0-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/50450nvdExploitThird Party AdvisoryVDB Entry
- www.sourcecodester.com/php/14241/online-event-booking-and-reservation-system-phpmysql.htmlnvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.