CVE-2026-10289: code-projects Hotel and Tourism Reservation System tour.php cross site scripting
A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10289?
CVE-2026-10289 has a medium severity rating of 4.3.
How do I fix CVE-2026-10289?
To fix CVE-2026-10289, ensure proper input validation and output encoding for user-supplied data in the affected parameters.
What type of vulnerability is CVE-2026-10289?
CVE-2026-10289 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2026-10289 be exploited remotely?
Yes, CVE-2026-10289 can be exploited remotely by manipulating the parameters in the tour.php file.
Which component is affected by CVE-2026-10289?
CVE-2026-10289 affects the tour.php file of the Code-projects Hotel and Tourism Reservation System version 1.0.