CVE-2026-3819

A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown function of the file /?page=manage_reservation of the component Reservation Management Module. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:resort_reservation_system:1.0:*:*:*:*:*:*:*

History

09 Mar 2026, 14:47

Type Values Removed Values Added
First Time Oretnom23 resort Reservation System
Oretnom23
References () https://medium.com/@rvpipalwa/stored-cross-site-scripting-xss-in-reservation-management-sourcecodester-resort-reservation-894ee77d7312 - () https://medium.com/@rvpipalwa/stored-cross-site-scripting-xss-in-reservation-management-sourcecodester-resort-reservation-894ee77d7312 - Exploit, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.349785 - () https://vuldb.com/?ctiid.349785 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.349785 - () https://vuldb.com/?id.349785 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.769578 - () https://vuldb.com/?submit.769578 - Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
CPE cpe:2.3:a:oretnom23:resort_reservation_system:1.0:*:*:*:*:*:*:*

09 Mar 2026, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 13:15

Updated : 2026-03-09 14:47


NVD link : CVE-2026-3819

Mitre link : CVE-2026-3819

CVE.ORG link : CVE-2026-3819


JSON object : View

Products Affected

oretnom23

  • resort_reservation_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')