A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.phpjabbers.com/shuttle-booking-software/ | product |
http://packetstormsecurity.com/files/175800 | third party advisory vdb entry |
https://github.com/bugsbd/CVE/tree/main/2023/CVE-2023-48172 | exploit |