Medium severity5.4NVD Advisory· Published Sep 12, 2022· Updated Jun 17, 2026
CVE-2022-36254
CVE-2022-36254
Description
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
Affected products
3- Range: = 1.0
- Range: = 1.0
- cpe:2.3:a:hotel_management_system_project:hotel_management_system:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- gist.github.com/ziyishen97/c464b459df73c4cef241e7ec774b7cf6nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.