CVE-2026-3819

A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown function of the file /?page=manage_reservation of the component Reservation Management Module. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:resort_reservation_system:1.0:*:*:*:*:*:*:*

History

29 Apr 2026, 01:00

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en SourceCodester Resort Reservation System 1.0. El elemento afectado es una función desconocida del archivo /?page=manage_reservation del componente Módulo de Gestión de Reservas. Dicha manipulación del argumento ID conduce a cross-site scripting. El ataque puede lanzarse de forma remota. El exploit ha sido divulgado al público y puede ser utilizado.

09 Mar 2026, 14:47

Type Values Removed Values Added
First Time Oretnom23 resort Reservation System
Oretnom23
References () https://medium.com/@rvpipalwa/stored-cross-site-scripting-xss-in-reservation-management-sourcecodester-resort-reservation-894ee77d7312 - () https://medium.com/@rvpipalwa/stored-cross-site-scripting-xss-in-reservation-management-sourcecodester-resort-reservation-894ee77d7312 - Exploit, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.349785 - () https://vuldb.com/?ctiid.349785 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.349785 - () https://vuldb.com/?id.349785 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.769578 - () https://vuldb.com/?submit.769578 - Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
CPE cpe:2.3:a:oretnom23:resort_reservation_system:1.0:*:*:*:*:*:*:*

09 Mar 2026, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 13:15

Updated : 2026-06-17 10:44


NVD link : CVE-2026-3819

Mitre link : CVE-2026-3819

CVE.ORG link : CVE-2026-3819


JSON object : View

Products Affected

oretnom23

  • resort_reservation_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')