CVE-2026-5705: code-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5705?
CVE-2026-5705 is classified as a cross-site scripting (XSS) vulnerability that can allow unauthorized script execution.
How do I fix CVE-2026-5705?
To fix CVE-2026-5705, you should sanitize and validate all user input in the /booknow.php endpoint to prevent injection of malicious scripts.
What impact does CVE-2026-5705 have on users?
CVE-2026-5705 can lead to security risks such as session hijacking, defacement of the website, and the potential compromise of user data.
Is there a patch available for CVE-2026-5705?
Currently, there is no official patch released by code-projects for CVE-2026-5705; manual mitigation is recommended.
Which version of Online Hotel Booking is affected by CVE-2026-5705?
CVE-2026-5705 affects version 1.0 of the code-projects Online Hotel Booking application.