Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-list.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/49135 | third party advisory vdb entry exploit |
https://packetstormsecurity.com/files/159786/Multi-Restaurant-Table-Reservation-System-1.0-Cross-Site-Scripting.html | third party advisory vdb entry exploit |
https://www.sourcecodester.com/php/14568/multi-restaurant-table-reservation-system-php-full-source-code.html | product |
https://github.com/yunaranyancat/poc-dump/tree/main/MultiRestaurantReservationSystem/1.0 | third party advisory exploit |